Vulnerability Details CVE-2016-9017
Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2016-9017
-
-
cpe:2.3:a:artifex:mujs:1.0.0
-
cpe:2.3:a:artifex:mujs:1.0.1
-
cpe:2.3:a:artifex:mujs:1.0.2
-
cpe:2.3:a:artifex:mujs:1.0.3
-
cpe:2.3:a:artifex:mujs:1.0.4
-
cpe:2.3:a:artifex:mujs:1.0.5
-
cpe:2.3:a:artifex:mujs:1.0.6
-
cpe:2.3:a:artifex:mujs:1.0.7
-
cpe:2.3:a:artifex:mujs:1.0.8
-
cpe:2.3:a:artifex:mujs:1.0.9
-
cpe:2.3:a:artifex:mujs:1.1.0
-
cpe:2.3:a:artifex:mujs:1.1.1
-
cpe:2.3:a:artifex:mujs:1.1.2
-
cpe:2.3:a:artifex:mujs:1.1.3
-
cpe:2.3:a:artifex:mujs:1.2.0