Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown

CVE-2024-25431

Disclosure Date: November 08, 2024 (last updated February 27, 2025)
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.
Attacker Value
Unknown

CVE-2023-40266

Disclosure Date: February 08, 2024 (last updated February 26, 2025)
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
Attacker Value
Unknown

CVE-2023-40265

Disclosure Date: February 08, 2024 (last updated February 26, 2025)
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
Attacker Value
Unknown

CVE-2023-52284

Disclosure Date: December 31, 2023 (last updated February 25, 2025)
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.
Attacker Value
Unknown

CVE-2023-48105

Disclosure Date: November 22, 2023 (last updated February 25, 2025)
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
Attacker Value
Unknown

CVE-2023-46331

Disclosure Date: October 23, 2023 (last updated February 25, 2025)
WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.
Attacker Value
Unknown

CVE-2023-46332

Disclosure Date: October 23, 2023 (last updated February 25, 2025)
WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
Attacker Value
Unknown

CVE-2023-31669

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
Attacker Value
Unknown

CVE-2023-31670

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.
Attacker Value
Unknown

CVE-2023-30300

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.