CVE-2019-16366: Moddable

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.

Affected products

Published 2019-09-16. Last modified 2026-06-17.