CVE-2018-11598: Espruino
High severity, CVSS 7.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or Out-of-bounds Read during syntax parsing of certain for loops in jsparse.c.
Affected products
- Espruino Espruino: before 1.99 (fixed in 1.99)
Published 2018-05-31. Last modified 2026-06-17.