lua records
17 published records for vendor lua.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-416 Use After Free2
- CWE-787 Out-of-bounds Write2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-15889No exploit | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memblua · lua · CWE-125 | Critical9.8 | — | 2.2% | Jul 21, 2020 |
37Monitor | CVE-2022-28805No exploit | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-basedlua · lua · CWE-125 | Critical9.1 | — | 3.0% | Apr 8, 2022 |
36Monitor | CVE-2020-15888No exploit | Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-baslua · lua · CWE-125 | High8.8 | — | 2.4% | Jul 21, 2020 |
35Monitor | CVE-2019-6706Proof of concept | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.lua · lua · CWE-416 | High7.5 | — | 17.2% | Jan 23, 2019 |
31Monitor | CVE-2022-33099No exploit | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.lua · lua · CWE-787 | High7.5 | — | 2.8% | Jul 1, 2022 |
31Monitor | CVE-2021-32918No exploit | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-400 | High7.5 | — | 2.1% | May 13, 2021 |
31Monitor | CVE-2020-24369No exploit | ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.lua · lua · CWE-476 | High7.5 | — | 1.7% | Aug 17, 2020 |
31Monitor | CVE-2020-24342No exploit | Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in alua · lua · CWE-119 | High7.8 | — | 1.1% | Aug 13, 2020 |
30Monitor | CVE-2021-45985No exploit | In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.lua · lua · CWE-787 | High7.5 | — | 1.4% | Apr 10, 2023 |
25Monitor | CVE-2021-44964No exploit | Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a clua · lua · CWE-416 | Medium6.3 | — | 1.0% | Mar 14, 2022 |
24Monitor | CVE-2014-5461No exploit | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial lua · lua · CWE-119 | Medium5.0 | — | 11.7% | Sep 4, 2014 |
23Monitor | CVE-2021-32921No exploit | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-362 | Medium5.9 | — | 1.6% | May 13, 2021 |
22Monitor | CVE-2020-24370Proof of concept | ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).lua · lua · CWE-191 | Medium5.3 | — | 3.8% | Aug 17, 2020 |
22Monitor | CVE-2020-24371No exploit | lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgalua · lua · CWE-763 | Medium5.3 | — | 1.7% | Aug 17, 2020 |
22Monitor | CVE-2021-43519No exploit | Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script filua · lua · CWE-674 | Medium5.5 | — | 1.2% | Nov 9, 2021 |
22Monitor | CVE-2020-15945No exploit | Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly lua · lua | Medium5.5 | — | 0.5% | Jul 24, 2020 |
22Monitor | CVE-2021-44647No exploit | Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servilua · lua · CWE-843 | Medium5.5 | — | 0.4% | Jan 11, 2022 |
- CVE-2020-1588940Plan
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memb
CriticalCVSS 9.8No exploitEPSS 2%lua · luaJul 21, 2020
- CVE-2022-2880537Monitor
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based
CriticalCVSS 9.1No exploitEPSS 3%lua · luaApr 8, 2022
- CVE-2020-1588836Monitor
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-bas
HighCVSS 8.8No exploitEPSS 2%lua · luaJul 21, 2020
- CVE-2019-670635Monitor
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.
HighCVSS 7.5Proof of conceptEPSS 17%lua · luaJan 23, 2019
- CVE-2022-3309931Monitor
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
HighCVSS 7.5No exploitEPSS 3%lua · luaJul 1, 2022
- CVE-2021-3291831Monitor
An issue was discovered in Prosody before 0.11.9.
HighCVSS 7.5No exploitEPSS 2%prosody · prosodyMay 13, 2021
- CVE-2020-2436931Monitor
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
HighCVSS 7.5No exploitEPSS 2%lua · luaAug 17, 2020
- CVE-2020-2434231Monitor
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a
HighCVSS 7.8No exploitEPSS 1%lua · luaAug 13, 2020
- CVE-2021-4598530Monitor
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
HighCVSS 7.5No exploitEPSS 1%lua · luaApr 10, 2023
- CVE-2021-4496425Monitor
Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a c
MediumCVSS 6.3No exploitEPSS 1%lua · luaMar 14, 2022
- CVE-2014-546124Monitor
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
MediumCVSS 5.0No exploitEPSS 12%lua · luaSep 4, 2014
- CVE-2021-3292123Monitor
An issue was discovered in Prosody before 0.11.9.
MediumCVSS 5.9No exploitEPSS 2%prosody · prosodyMay 13, 2021
- CVE-2020-2437022Monitor
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
MediumCVSS 5.3Proof of conceptEPSS 4%lua · luaAug 17, 2020
- CVE-2020-2437122Monitor
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectga
MediumCVSS 5.3No exploitEPSS 2%lua · luaAug 17, 2020
- CVE-2021-4351922Monitor
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script fi
MediumCVSS 5.5No exploitEPSS 1%lua · luaNov 9, 2021
- CVE-2020-1594522Monitor
Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly
MediumCVSS 5.5No exploitEPSS 1%lua · luaJul 24, 2020
- CVE-2021-4464722Monitor
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servi
MediumCVSS 5.5No exploitEPSS 0%lua · luaJan 11, 2022