← Vulnerability feed

Vulnerability record · CVE-2019-11411 · published 22 April 2019

CVE-2019-11411: Artifex mujs out-of-bounds write vulnerability

Artifex · Mujs

An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.

9.8 CVSS 3.0 Critical EPSS 3.3% · top 12.0% CWE-787 · Out-of-bounds write
9.8CVSS 3.0 base score, v2 7.5
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.ghostscript.com/cgi-bin/findgit.cgi?da632ca08f240590d2dec786722ed08486ce1be6 PatchVendor Advisory
http://www.securityfocus.com/bid/108093 Third Party AdvisoryVDB Entry
https://bugs.ghostscript.com/show_bug.cgi?id=700938 Issue TrackingPermissions RequiredVendor Advisory
https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6 PatchThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3RQXMWEOWCGLOLFBQSXBM3M
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67PMOZV4DLVL2KGU2SV724Q
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MFCRO74ORRIVWNVAX2MAMRY
https://security.gentoo.org/glsa/202007-52
http://www.ghostscript.com/cgi-bin/findgit.cgi?da632ca08f240590d2dec786722ed08486ce1be6 PatchVendor Advisory
http://www.securityfocus.com/bid/108093 Third Party AdvisoryVDB Entry
https://bugs.ghostscript.com/show_bug.cgi?id=700938 Issue TrackingPermissions RequiredVendor Advisory
https://github.com/ccxvii/mujs/commit/da632ca08f240590d2dec786722ed08486ce1be6 PatchThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3RQXMWEOWCGLOLFBQSXBM3M
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67PMOZV4DLVL2KGU2SV724Q
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MFCRO74ORRIVWNVAX2MAMRY
https://security.gentoo.org/glsa/202007-52

Track CVE-2019-11411 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33797Artifex mujs memory buffer overflow vulnerabilityBuffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent…EPSS 0.81%9.8CVE-2021-45005Artifex mujs out-of-bounds write vulnerabilityArtifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.EPSS 1.4%9.8CVE-2019-12798Artifex mujs vulnerabilityAn issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the …EPSS 1.7%9.8CVE-2016-10133Artifex mujs memory buffer overflow vulnerabilityHeap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by …EPSS 2.4%9.8CVE-2016-10141Artifex mujs integer overflow vulnerabilityAn integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb86…EPSS 3.6%9.8CVE-2016-7505Artifex mujs memory buffer overflow vulnerabilityA buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before 8c805b4eb19cf2af689c860b77e6111d2ee439d5. A succ…EPSS 3.0%9.8CVE-2016-7504Artifex mujs use after free vulnerabilityA use-after-free vulnerability was observed in Rp_toString function of Artifex Software, Inc. MuJS before 5c337af4b3df80cf967e4f9f6a21522de84b392a. A…EPSS 2.8%8.8CVE-2022-44789Artifex mujs out-of-bounds write vulnerabilityA logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2019-11411), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.