An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045. The attack requires a regular expression with nested repetition. A successful exploitation of this issue can lead to code execution or a denial of service (buffer overflow) condition.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:artifex:mujs:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "2017-01-12"
}
],
"source": "CPE_RANGE",
"vendor_product": "artifex:mujs"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10141.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "21665381433267176073786273999301673535",
"length": 1849
},
"id": "CVE-2016-10141-18fbd91e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ccxvii/mujs/commit/fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045",
"target": {
"file": "regexp.c",
"function": "regcompx"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"225263007365615047898124717984119051470",
"182627581303940126331269315450078115057",
"287377703607885720243941633031137605297",
"1143997269387904603428049611626258392",
"22847113636774639395833636344462465309",
"128575722281893391915868926441471092768",
"268930328801580875342485121012054873799",
"119858624712182565703084916262494853002",
"149245634014959136794942973395159263601",
"212473203839506198042656972537004791522",
"46023704794594934482714449271268896223",
"335062248623805344353543533958014922099",
"36230755849103343879284620470044720577",
"335548601696821577883889348581089471206",
"3054982730441853285546258208913513720",
"213434136540516137792066082495615431669",
"59027124774714021233129173741449761349",
"118419066622540623035455411107862023570",
"226972520694479192572851519726367601097",
"104473724083991267704157363479231322194",
"238280354580894821092353541903773681391",
"237226867751116882479468860212953864555",
"39850652646120630185976066198498282403",
"15705594932027223634581450172343817115",
"147429703078009798416777670018770260348",
"334903975255451535072585687883999078478",
"14441272235272763020535257309449554147",
"255409870872908450330544629791049807533",
"122671439954352255158330119419467103616",
"73338450709472269276036460069025297596",
"119058402507017171688483550317322314191",
"316333102932808889873545543235005172353",
"204920813210045205941339070603887155272",
"282695124248159874392675006425342985152",
"123411656109150016642196111718284943028",
"243583044392374499455498712613080914834",
"157403118353992465929937704183092903859"
],
"threshold": 0.9
},
"id": "CVE-2016-10141-c66cfd9f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/ccxvii/mujs/commit/fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045",
"target": {
"file": "regexp.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "9255628377889134588912964713711699846",
"length": 669
},
"id": "CVE-2016-10141-d03fdadc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ccxvii/mujs/commit/fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045",
"target": {
"file": "regexp.c",
"function": "count"
}
}
]
"2026-09-30T08:02:08Z"