Skip to content
Noroxi

lua records

17 published records for vendor lua.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

17 records
  • Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memb

    CriticalCVSS 9.8No exploitEPSS 2%

    lua · luaJul 21, 2020

  • singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based

    CriticalCVSS 9.1No exploitEPSS 3%

    lua · luaApr 8, 2022

  • Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-bas

    HighCVSS 8.8No exploitEPSS 2%

    lua · luaJul 21, 2020

  • CVE-2019-6706
    35Monitor

    Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.

    HighCVSS 7.5Proof of conceptEPSS 17%

    lua · luaJan 23, 2019

  • An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

    HighCVSS 7.5No exploitEPSS 3%

    lua · luaJul 1, 2022

  • An issue was discovered in Prosody before 0.11.9.

    HighCVSS 7.5No exploitEPSS 2%

    prosody · prosodyMay 13, 2021

  • ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.

    HighCVSS 7.5No exploitEPSS 2%

    lua · luaAug 17, 2020

  • Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a

    HighCVSS 7.8No exploitEPSS 1%

    lua · luaAug 13, 2020

  • In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.

    HighCVSS 7.5No exploitEPSS 1%

    lua · luaApr 10, 2023

  • Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a c

    MediumCVSS 6.3No exploitEPSS 1%

    lua · luaMar 14, 2022

  • CVE-2014-5461
    24Monitor

    Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial

    MediumCVSS 5.0No exploitEPSS 12%

    lua · luaSep 4, 2014

  • An issue was discovered in Prosody before 0.11.9.

    MediumCVSS 5.9No exploitEPSS 2%

    prosody · prosodyMay 13, 2021

  • ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).

    MediumCVSS 5.3Proof of conceptEPSS 4%

    lua · luaAug 17, 2020

  • lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectga

    MediumCVSS 5.3No exploitEPSS 2%

    lua · luaAug 17, 2020

  • Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script fi

    MediumCVSS 5.5No exploitEPSS 1%

    lua · luaNov 9, 2021

  • Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly

    MediumCVSS 5.5No exploitEPSS 1%

    lua · luaJul 24, 2020

  • Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servi

    MediumCVSS 5.5No exploitEPSS 0%

    lua · luaJan 11, 2022