Show filters
247 Total Results
Displaying 111-120 of 247
Sort by:
Attacker Value
Unknown
CVE-2018-17980
Disclosure Date: October 15, 2018 (last updated November 27, 2024)
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan horse code is executed. (The directory could, in general, be on a local filesystem or a network share.).
0
Attacker Value
Unknown
CVE-2018-17293
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL pointer dereference) or possibly have unspecified other impact by crafting certain WebAssembly files.
0
Attacker Value
Unknown
CVE-2018-17292
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Denial of Service (application crash caused by out-of-bounds read) by crafting a file that has fewer than 4 bytes.
0
Attacker Value
Unknown
CVE-2018-16767
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::popAndValidateOperand.
0
Attacker Value
Unknown
CVE-2018-16765
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::else_.
0
Attacker Value
Unknown
CVE-2018-16768
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in IR::FunctionValidationContext::end.
0
Attacker Value
Unknown
CVE-2018-16770
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because a certain new_allocator allocate call fails.
0
Attacker Value
Unknown
CVE-2018-16769
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because libRuntime.so!llvm::InstructionCombiningPass::runOnFunction is mishandled.
0
Attacker Value
Unknown
CVE-2018-16764
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::FunctionValidationContext::catch_all heap-based buffer over-read.
0
Attacker Value
Unknown
CVE-2018-16766
Disclosure Date: September 10, 2018 (last updated November 27, 2024)
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because Errors::unreachable() is reached.
0