Skip to content
Noroxi

bytecodealliance records

55 published records for vendor bytecodealliance.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
85.5%
Median publish → KEV
No record has entered KEV

All records

55 records
  • Guest-controlled out-of-bounds read/write on x86_64 in wasmtime

    CriticalCVSS 9.9No exploitEPSS 1%

    bytecodealliance · cranelift-codegenMar 8, 2023

  • Use after free in Wasmtime

    CriticalCVSS 9.8No exploitEPSS 1%

    bytecodealliance · wasmtimeMar 31, 2022

  • wasmtime_trap_code C API function has out of bounds write vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    bytecodealliance · wasmtimeNov 10, 2022

  • Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

    CriticalCVSS 9.0No exploitEPSS 0%

    bytecodealliance · wasmtimeApr 9, 2026

  • Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

    CriticalCVSS 9.0No exploitEPSS 0%

    bytecodealliance · wasmtimeApr 9, 2026

  • Use After Free in Wasmtime

    HighCVSS 8.8No exploitEPSS 1%

    bytecodealliance · cranelift-codegenJul 21, 2022

  • Memory access due to code generation flaw in Cranelift module

    HighCVSS 8.8No exploitEPSS 0%

    bytecodealliance · cranelift-codegenMay 24, 2021

  • Wasmtime has Undefined Behavior in Rust runtime functions

    HighCVSS 8.8No exploitEPSS 0%

    bytecodealliance · wasmtimeApr 27, 2023

  • Wasmtime vulnerable to data leakage between instances in the pooling allocator

    HighCVSS 8.6No exploitEPSS 1%

    bytecodealliance · wasmtimeNov 10, 2022

  • Use After Free in lucet

    HighCVSS 8.1No exploitEPSS 2%

    bytecodealliance · lucetNov 29, 2021

  • Invalid drop of partially-initialized instances in wasmtime

    HighCVSS 8.1Proof of conceptEPSS 1%

    bytecodealliance · wasmtimeFeb 16, 2022

  • An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges

    HighCVSS 7.8No exploitEPSS 1%

    bytecodealliance · webassembly micro runtimeNov 8, 2024

  • An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of

    HighCVSS 7.5No exploitEPSS 1%

    bytecodealliance · webassembly micro runtimeNov 22, 2023

  • Cranelift vulnerable to miscompilation of constant values in division on AArch64

    HighCVSS 7.5No exploitEPSS 1%

    bytecodealliance · cranelift-codegenJul 22, 2022

  • An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to ca

    HighCVSS 7.5No exploitEPSS 1%

    bytecodealliance · webassembly micro runtimeMay 6, 2024

  • wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_res

    HighCVSS 7.5No exploitEPSS 1%

    bytecodealliance · webassembly micro runtimeNov 8, 2024

  • Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

    HighCVSS 7.5No exploitEPSS 1%

    bytecodealliance · wasmtimeJun 15, 2026

  • Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configuration

    HighCVSS 7.4No exploitEPSS 1%

    bytecodealliance · wasmtimeNov 10, 2022

  • WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode

    HighCVSS 7.4No exploitEPSS 0%

    bytecodealliance · webassembly micro runtimeNov 25, 2025

  • iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature

    HighCVSS 7.0No exploitEPSS 0%

    bytecodealliance · webassembly micro runtimeMay 15, 2025

  • Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

    MediumCVSS 6.9No exploitEPSS 1%

    bytecodealliance · wasmtimeFeb 24, 2026

  • Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

    MediumCVSS 6.9No exploitEPSS 1%

    bytecodealliance · wasmtimeFeb 24, 2026

  • WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified

    MediumCVSS 6.9No exploitEPSS 1%

    bytecodealliance · webassembly micro runtimeJul 29, 2025

  • Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

    MediumCVSS 6.9No exploitEPSS 1%

    bytecodealliance · wasmtimeFeb 24, 2026

  • Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

    MediumCVSS 6.9No exploitEPSS 0%

    bytecodealliance · wasmtimeApr 9, 2026