Show filters
43 Total Results
Displaying 1-10 of 43
Sort by:
Attacker Value
Unknown

CVE-2023-46331

Disclosure Date: October 23, 2023 (last updated October 31, 2023)
WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.
Attacker Value
Unknown

CVE-2023-46332

Disclosure Date: October 23, 2023 (last updated October 31, 2023)
WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
Attacker Value
Unknown

CVE-2020-18382

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.
Attacker Value
Unknown

CVE-2020-18378

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
Attacker Value
Unknown

CVE-2023-31669

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
Attacker Value
Unknown

CVE-2023-31670

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.
Attacker Value
Unknown

CVE-2023-27119

Disclosure Date: March 10, 2023 (last updated October 08, 2023)
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
Attacker Value
Unknown

CVE-2023-27117

Disclosure Date: March 10, 2023 (last updated October 08, 2023)
WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
Attacker Value
Unknown

CVE-2023-27116

Disclosure Date: March 10, 2023 (last updated October 08, 2023)
WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType.
Attacker Value
Unknown

CVE-2023-27115

Disclosure Date: March 10, 2023 (last updated October 08, 2023)
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.