Записи bytecodealliance
55 опубликованных записей вендора bytecodealliance.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 85,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read8
- CWE-416 Use After Free5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-787 Out-of-bounds Write3
- CWE-193 Off-by-one Error2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
55 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-26489Эксплойта нет | Guest-controlled out-of-bounds read/write on x86_64 in wasmtimebytecodealliance · cranelift-codegen · CWE-125 | Критическая9,9 | — | 1,3 % | 8 мар. 2023 г. |
39Наблюдать | CVE-2022-24791Эксплойта нет | Use after free in Wasmtimebytecodealliance · wasmtime · CWE-416 | Критическая9,8 | — | 1,2 % | 31 мар. 2022 г. |
39Наблюдать | CVE-2022-39394Эксплойта нет | wasmtime_trap_code C API function has out of bounds write vulnerabilitybytecodealliance · wasmtime · CWE-787 | Критическая9,8 | — | 0,3 % | 10 нояб. 2022 г. |
36Наблюдать | CVE-2026-34987Эксплойта нет | Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessbytecodealliance · wasmtime · CWE-125 | Критическая9,0 | — | 0,5 % | 9 апр. 2026 г. |
36Наблюдать | CVE-2026-34971Эксплойта нет | Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Craneliftbytecodealliance · wasmtime · CWE-125 | Критическая9,0 | — | 0,4 % | 9 апр. 2026 г. |
35Наблюдать | CVE-2022-31146Эксплойта нет | Use After Free in Wasmtimebytecodealliance · cranelift-codegen · CWE-416 | Высокая8,8 | — | 1,2 % | 21 июл. 2022 г. |
35Наблюдать | CVE-2021-32629Эксплойта нет | Memory access due to code generation flaw in Cranelift modulebytecodealliance · cranelift-codegen · CWE-788 | Высокая8,8 | — | 0,5 % | 24 мая 2021 г. |
35Наблюдать | CVE-2023-30624Эксплойта нет | Wasmtime has Undefined Behavior in Rust runtime functionsbytecodealliance · wasmtime · CWE-758 | Высокая8,8 | — | 0,5 % | 27 апр. 2023 г. |
34Наблюдать | CVE-2022-39393Эксплойта нет | Wasmtime vulnerable to data leakage between instances in the pooling allocatorbytecodealliance · wasmtime · CWE-226 | Высокая8,6 | — | 0,7 % | 10 нояб. 2022 г. |
32Наблюдать | CVE-2021-43790Эксплойта нет | Use After Free in lucetbytecodealliance · lucet · CWE-416 | Высокая8,1 | — | 1,6 % | 29 нояб. 2021 г. |
32Наблюдать | CVE-2022-23636Proof of concept | Invalid drop of partially-initialized instances in wasmtimebytecodealliance · wasmtime · CWE-824 | Высокая8,1 | — | 0,8 % | 16 февр. 2022 г. |
31Наблюдать | CVE-2024-25431Эксплойта нет | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privilegesbytecodealliance · webassembly micro runtime · CWE-125 | Высокая7,8 | — | 0,6 % | 8 нояб. 2024 г. |
30Наблюдать | CVE-2023-48105Эксплойта нет | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of bytecodealliance · webassembly micro runtime · CWE-787 | Высокая7,5 | — | 1,0 % | 22 нояб. 2023 г. |
30Наблюдать | CVE-2022-31169Эксплойта нет | Cranelift vulnerable to miscompilation of constant values in division on AArch64bytecodealliance · cranelift-codegen · CWE-682 | Высокая7,5 | — | 0,9 % | 22 июл. 2022 г. |
30Наблюдать | CVE-2024-34251Эксплойта нет | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cabytecodealliance · webassembly micro runtime · CWE-125 | Высокая7,5 | — | 0,8 % | 6 мая 2024 г. |
30Наблюдать | CVE-2024-27532Эксплойта нет | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_resbytecodealliance · webassembly micro runtime · CWE-476 | Высокая7,5 | — | 0,5 % | 8 нояб. 2024 г. |
30Наблюдать | CVE-2026-47261Эксплойта нет | Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionbytecodealliance · wasmtime · CWE-284 | Высокая7,5 | — | 0,5 % | 15 июн. 2026 г. |
29Наблюдать | CVE-2022-39392Эксплойта нет | Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configurationbytecodealliance · wasmtime · CWE-119 | Высокая7,4 | — | 0,6 % | 10 нояб. 2022 г. |
29Наблюдать | CVE-2025-64713Эксплойта нет | WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcodebytecodealliance · webassembly micro runtime · CWE-119 | Высокая7,4 | — | 0,3 % | 25 нояб. 2025 г. |
28Наблюдать | CVE-2025-43853Эксплойта нет | iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi featurebytecodealliance · webassembly micro runtime · CWE-61 | Высокая7,0 | — | 0,3 % | 15 мая 2025 г. |
27Наблюдать | CVE-2026-27572Эксплойта нет | Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instancebytecodealliance · wasmtime · CWE-770 | Средняя6,9 | — | 0,7 % | 24 февр. 2026 г. |
27Наблюдать | CVE-2026-27204Эксплойта нет | Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionbytecodealliance · wasmtime · CWE-400 | Средняя6,9 | — | 0,7 % | 24 февр. 2026 г. |
27Наблюдать | CVE-2025-54126Эксплойта нет | WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specifiedbytecodealliance · webassembly micro runtime · CWE-668 | Средняя6,9 | — | 0,6 % | 29 июл. 2025 г. |
27Наблюдать | CVE-2026-27195Эксплойта нет | Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` futurebytecodealliance · wasmtime · CWE-755 | Средняя6,9 | — | 0,6 % | 24 февр. 2026 г. |
27Наблюдать | CVE-2026-34941Эксплойта нет | Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingbytecodealliance · wasmtime · CWE-125 | Средняя6,9 | — | 0,5 % | 9 апр. 2026 г. |
- CVE-2023-2648939Наблюдать
Guest-controlled out-of-bounds read/write on x86_64 in wasmtime
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %bytecodealliance · cranelift-codegen8 мар. 2023 г.
- CVE-2022-2479139Наблюдать
Use after free in Wasmtime
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bytecodealliance · wasmtime31 мар. 2022 г.
- CVE-2022-3939439Наблюдать
wasmtime_trap_code C API function has out of bounds write vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %bytecodealliance · wasmtime10 нояб. 2022 г.
- CVE-2026-3498736Наблюдать
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %bytecodealliance · wasmtime9 апр. 2026 г.
- CVE-2026-3497136Наблюдать
Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %bytecodealliance · wasmtime9 апр. 2026 г.
- CVE-2022-3114635Наблюдать
Use After Free in Wasmtime
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bytecodealliance · cranelift-codegen21 июл. 2022 г.
- CVE-2021-3262935Наблюдать
Memory access due to code generation flaw in Cranelift module
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bytecodealliance · cranelift-codegen24 мая 2021 г.
- CVE-2023-3062435Наблюдать
Wasmtime has Undefined Behavior in Rust runtime functions
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bytecodealliance · wasmtime27 апр. 2023 г.
- CVE-2022-3939334Наблюдать
Wasmtime vulnerable to data leakage between instances in the pooling allocator
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %bytecodealliance · wasmtime10 нояб. 2022 г.
- CVE-2021-4379032Наблюдать
Use After Free in lucet
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %bytecodealliance · lucet29 нояб. 2021 г.
- CVE-2022-2363632Наблюдать
Invalid drop of partially-initialized instances in wasmtime
ВысокаяCVSS 8,1Proof of conceptEPSS 1 %bytecodealliance · wasmtime16 февр. 2022 г.
- CVE-2024-2543131Наблюдать
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %bytecodealliance · webassembly micro runtime8 нояб. 2024 г.
- CVE-2023-4810530Наблюдать
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bytecodealliance · webassembly micro runtime22 нояб. 2023 г.
- CVE-2022-3116930Наблюдать
Cranelift vulnerable to miscompilation of constant values in division on AArch64
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bytecodealliance · cranelift-codegen22 июл. 2022 г.
- CVE-2024-3425130Наблюдать
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to ca
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bytecodealliance · webassembly micro runtime6 мая 2024 г.
- CVE-2024-2753230Наблюдать
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_res
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bytecodealliance · webassembly micro runtime8 нояб. 2024 г.
- CVE-2026-4726130Наблюдать
Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bytecodealliance · wasmtime15 июн. 2026 г.
- CVE-2022-3939229Наблюдать
Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configuration
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %bytecodealliance · wasmtime10 нояб. 2022 г.
- CVE-2025-6471329Наблюдать
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %bytecodealliance · webassembly micro runtime25 нояб. 2025 г.
- CVE-2025-4385328Наблюдать
iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %bytecodealliance · webassembly micro runtime15 мая 2025 г.
- CVE-2026-2757227Наблюдать
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
СредняяCVSS 6,9Эксплойта нетEPSS 1 %bytecodealliance · wasmtime24 февр. 2026 г.
- CVE-2026-2720427Наблюдать
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
СредняяCVSS 6,9Эксплойта нетEPSS 1 %bytecodealliance · wasmtime24 февр. 2026 г.
- CVE-2025-5412627Наблюдать
WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
СредняяCVSS 6,9Эксплойта нетEPSS 1 %bytecodealliance · webassembly micro runtime29 июл. 2025 г.
- CVE-2026-2719527Наблюдать
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
СредняяCVSS 6,9Эксплойта нетEPSS 1 %bytecodealliance · wasmtime24 февр. 2026 г.
- CVE-2026-3494127Наблюдать
Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
СредняяCVSS 6,9Эксплойта нетEPSS 0 %bytecodealliance · wasmtime9 апр. 2026 г.