Multiple vulnerabilities have been found in quickjs-ng, the worst of which could result in arbitrary code execution.
Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 release.
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c.
Multiple vulnerabilities have been found in FreeType, one of which includes information leak.