Записи lua
17 опубликованных записей вендора lua.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-416 Use After Free2
- CWE-787 Out-of-bounds Write2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-15889Эксплойта нет | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memblua · lua · CWE-125 | Критическая9,8 | — | 2,2 % | 21 июл. 2020 г. |
37Наблюдать | CVE-2022-28805Эксплойта нет | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-basedlua · lua · CWE-125 | Критическая9,1 | — | 3,0 % | 8 апр. 2022 г. |
36Наблюдать | CVE-2020-15888Эксплойта нет | Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-baslua · lua · CWE-125 | Высокая8,8 | — | 2,4 % | 21 июл. 2020 г. |
35Наблюдать | CVE-2019-6706Proof of concept | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.lua · lua · CWE-416 | Высокая7,5 | — | 17,2 % | 23 янв. 2019 г. |
31Наблюдать | CVE-2022-33099Эксплойта нет | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.lua · lua · CWE-787 | Высокая7,5 | — | 2,8 % | 1 июл. 2022 г. |
31Наблюдать | CVE-2021-32918Эксплойта нет | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-400 | Высокая7,5 | — | 2,1 % | 13 мая 2021 г. |
31Наблюдать | CVE-2020-24369Эксплойта нет | ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.lua · lua · CWE-476 | Высокая7,5 | — | 1,7 % | 17 авг. 2020 г. |
31Наблюдать | CVE-2020-24342Эксплойта нет | Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in alua · lua · CWE-119 | Высокая7,8 | — | 1,1 % | 13 авг. 2020 г. |
30Наблюдать | CVE-2021-45985Эксплойта нет | In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.lua · lua · CWE-787 | Высокая7,5 | — | 1,4 % | 10 апр. 2023 г. |
25Наблюдать | CVE-2021-44964Эксплойта нет | Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a clua · lua · CWE-416 | Средняя6,3 | — | 1,0 % | 14 мар. 2022 г. |
24Наблюдать | CVE-2014-5461Эксплойта нет | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial lua · lua · CWE-119 | Средняя5,0 | — | 11,7 % | 4 сент. 2014 г. |
23Наблюдать | CVE-2021-32921Эксплойта нет | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-362 | Средняя5,9 | — | 1,6 % | 13 мая 2021 г. |
22Наблюдать | CVE-2020-24370Proof of concept | ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).lua · lua · CWE-191 | Средняя5,3 | — | 3,8 % | 17 авг. 2020 г. |
22Наблюдать | CVE-2020-24371Эксплойта нет | lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgalua · lua · CWE-763 | Средняя5,3 | — | 1,7 % | 17 авг. 2020 г. |
22Наблюдать | CVE-2021-43519Эксплойта нет | Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script filua · lua · CWE-674 | Средняя5,5 | — | 1,2 % | 9 нояб. 2021 г. |
22Наблюдать | CVE-2020-15945Эксплойта нет | Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly lua · lua | Средняя5,5 | — | 0,5 % | 24 июл. 2020 г. |
22Наблюдать | CVE-2021-44647Эксплойта нет | Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servilua · lua · CWE-843 | Средняя5,5 | — | 0,4 % | 11 янв. 2022 г. |
- CVE-2020-1588940В плане
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memb
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lua · lua21 июл. 2020 г.
- CVE-2022-2880537Наблюдать
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %lua · lua8 апр. 2022 г.
- CVE-2020-1588836Наблюдать
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-bas
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %lua · lua21 июл. 2020 г.
- CVE-2019-670635Наблюдать
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.
ВысокаяCVSS 7,5Proof of conceptEPSS 17 %lua · lua23 янв. 2019 г.
- CVE-2022-3309931Наблюдать
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lua · lua1 июл. 2022 г.
- CVE-2021-3291831Наблюдать
An issue was discovered in Prosody before 0.11.9.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %prosody · prosody13 мая 2021 г.
- CVE-2020-2436931Наблюдать
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %lua · lua17 авг. 2020 г.
- CVE-2020-2434231Наблюдать
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %lua · lua13 авг. 2020 г.
- CVE-2021-4598530Наблюдать
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lua · lua10 апр. 2023 г.
- CVE-2021-4496425Наблюдать
Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a c
СредняяCVSS 6,3Эксплойта нетEPSS 1 %lua · lua14 мар. 2022 г.
- CVE-2014-546124Наблюдать
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
СредняяCVSS 5,0Эксплойта нетEPSS 12 %lua · lua4 сент. 2014 г.
- CVE-2021-3292123Наблюдать
An issue was discovered in Prosody before 0.11.9.
СредняяCVSS 5,9Эксплойта нетEPSS 2 %prosody · prosody13 мая 2021 г.
- CVE-2020-2437022Наблюдать
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
СредняяCVSS 5,3Proof of conceptEPSS 4 %lua · lua17 авг. 2020 г.
- CVE-2020-2437122Наблюдать
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectga
СредняяCVSS 5,3Эксплойта нетEPSS 2 %lua · lua17 авг. 2020 г.
- CVE-2021-4351922Наблюдать
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script fi
СредняяCVSS 5,5Эксплойта нетEPSS 1 %lua · lua9 нояб. 2021 г.
- CVE-2020-1594522Наблюдать
Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly
СредняяCVSS 5,5Эксплойта нетEPSS 1 %lua · lua24 июл. 2020 г.
- CVE-2021-4464722Наблюдать
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servi
СредняяCVSS 5,5Эксплойта нетEPSS 0 %lua · lua11 янв. 2022 г.