Show filters
68 Total Results
Displaying 41-50 of 68
Sort by:
Attacker Value
Unknown
CVE-2020-24372
Disclosure Date: August 17, 2020 (last updated February 21, 2025)
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
0
Attacker Value
Unknown
CVE-2020-24370
Disclosure Date: August 17, 2020 (last updated February 21, 2025)
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
0
Attacker Value
Unknown
CVE-2020-24369
Disclosure Date: August 17, 2020 (last updated February 21, 2025)
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2020-24342
Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
0
Attacker Value
Unknown
CVE-2020-15945
Disclosure Date: July 24, 2020 (last updated February 21, 2025)
Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.
0
Attacker Value
Unknown
CVE-2020-15890
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
0
Attacker Value
Unknown
CVE-2020-15888
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
0
Attacker Value
Unknown
CVE-2020-15889
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.
0
Attacker Value
Unknown
CVE-2020-2935
Disclosure Date: April 15, 2020 (last updated November 27, 2024)
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Hedge Management and IFRS Valuations. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Hedge Management and IFRS Valuations accessible data as well as unauthorized read access to a subset of Oracle Financial Services Hedge Management and IFRS Valuations accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
0
Attacker Value
Unknown
CVE-2020-9432
Disclosure Date: February 27, 2020 (last updated February 21, 2025)
openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values.
0