Moonjit Project maintains a lightweight Lua just-in-time compiler designed for embedded and resource-constrained environments, with disclosed vulnerabilities centered on the core Moonjit runtime. The observed weakness class involves type-confusion conditions in the language runtime, which reflects the memory-layout and type-casting complexity inherent to dynamic language implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moonjit Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19391CRITICAL In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, becau | Nov 29, 2019 | 9.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moonjit Project.
Media articles that mention a CVE ID that affects a product developed by Moonjit Project — matched by CVE ID, not by vendor name.