CVE-2016-10141
9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045. The attack requires a regular expression with nested repetition. A successful exploitation of this issue can lead to code execution or a denial of service (buffer overflow) condition.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.65% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-01-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| artifex | mujs |
References
- http://git.ghostscript.com/?p=mujs.git%3Bh=fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045
- http://www.securityfocus.com/bid/95876
- https://bugs.ghostscript.com/show_bug.cgi?id=697448
- http://git.ghostscript.com/?p=mujs.git%3Bh=fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045
- http://www.securityfocus.com/bid/95876
- https://bugs.ghostscript.com/show_bug.cgi?id=697448
→ the Explorer · watch your stack · NVD