CVE-2018-1000655: Jsish

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can result in Crash due to segmentation fault. This attack appear to be exploitable via a crafted javascript code. This vulnerability appears to have been fixed in 2.4.67.

Affected products

  • Jsish Jsish: version 2.4.65 only

Published 2018-08-20. Last modified 2026-06-17.