İçeriğe atla
Noroxi

bytecodealliance kayıtları

bytecodealliance üreticisine ait 55 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%85,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

55 kayıt
  • CVE-2023-26489
    39İzleyin

    Guest-controlled out-of-bounds read/write on x86_64 in wasmtime

    KritikCVSS 9,9İstismar yokEPSS %1

    bytecodealliance · cranelift-codegen8 Mar 2023

  • CVE-2022-24791
    39İzleyin

    Use after free in Wasmtime

    KritikCVSS 9,8İstismar yokEPSS %1

    bytecodealliance · wasmtime31 Mar 2022

  • CVE-2022-39394
    39İzleyin

    wasmtime_trap_code C API function has out of bounds write vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    bytecodealliance · wasmtime10 Kas 2022

  • CVE-2026-34987
    36İzleyin

    Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

    KritikCVSS 9,0İstismar yokEPSS %0

    bytecodealliance · wasmtime9 Nis 2026

  • CVE-2026-34971
    36İzleyin

    Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

    KritikCVSS 9,0İstismar yokEPSS %0

    bytecodealliance · wasmtime9 Nis 2026

  • CVE-2022-31146
    35İzleyin

    Use After Free in Wasmtime

    YüksekCVSS 8,8İstismar yokEPSS %1

    bytecodealliance · cranelift-codegen21 Tem 2022

  • CVE-2021-32629
    35İzleyin

    Memory access due to code generation flaw in Cranelift module

    YüksekCVSS 8,8İstismar yokEPSS %0

    bytecodealliance · cranelift-codegen24 May 2021

  • CVE-2023-30624
    35İzleyin

    Wasmtime has Undefined Behavior in Rust runtime functions

    YüksekCVSS 8,8İstismar yokEPSS %0

    bytecodealliance · wasmtime27 Nis 2023

  • CVE-2022-39393
    34İzleyin

    Wasmtime vulnerable to data leakage between instances in the pooling allocator

    YüksekCVSS 8,6İstismar yokEPSS %1

    bytecodealliance · wasmtime10 Kas 2022

  • CVE-2021-43790
    32İzleyin

    Use After Free in lucet

    YüksekCVSS 8,1İstismar yokEPSS %2

    bytecodealliance · lucet29 Kas 2021

  • CVE-2022-23636
    32İzleyin

    Invalid drop of partially-initialized instances in wasmtime

    YüksekCVSS 8,1Kavram kanıtıEPSS %1

    bytecodealliance · wasmtime16 Şub 2022

  • CVE-2024-25431
    31İzleyin

    An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges

    YüksekCVSS 7,8İstismar yokEPSS %1

    bytecodealliance · webassembly micro runtime8 Kas 2024

  • CVE-2023-48105
    30İzleyin

    An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of

    YüksekCVSS 7,5İstismar yokEPSS %1

    bytecodealliance · webassembly micro runtime22 Kas 2023

  • CVE-2022-31169
    30İzleyin

    Cranelift vulnerable to miscompilation of constant values in division on AArch64

    YüksekCVSS 7,5İstismar yokEPSS %1

    bytecodealliance · cranelift-codegen22 Tem 2022

  • CVE-2024-34251
    30İzleyin

    An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to ca

    YüksekCVSS 7,5İstismar yokEPSS %1

    bytecodealliance · webassembly micro runtime6 May 2024

  • CVE-2024-27532
    30İzleyin

    wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_res

    YüksekCVSS 7,5İstismar yokEPSS %1

    bytecodealliance · webassembly micro runtime8 Kas 2024

  • CVE-2026-47261
    30İzleyin

    Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

    YüksekCVSS 7,5İstismar yokEPSS %1

    bytecodealliance · wasmtime15 Haz 2026

  • CVE-2022-39392
    29İzleyin

    Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configuration

    YüksekCVSS 7,4İstismar yokEPSS %1

    bytecodealliance · wasmtime10 Kas 2022

  • CVE-2025-64713
    29İzleyin

    WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode

    YüksekCVSS 7,4İstismar yokEPSS %0

    bytecodealliance · webassembly micro runtime25 Kas 2025

  • CVE-2025-43853
    28İzleyin

    iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature

    YüksekCVSS 7,0İstismar yokEPSS %0

    bytecodealliance · webassembly micro runtime15 May 2025

  • CVE-2026-27572
    27İzleyin

    Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

    OrtaCVSS 6,9İstismar yokEPSS %1

    bytecodealliance · wasmtime24 Şub 2026

  • CVE-2026-27204
    27İzleyin

    Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

    OrtaCVSS 6,9İstismar yokEPSS %1

    bytecodealliance · wasmtime24 Şub 2026

  • CVE-2025-54126
    27İzleyin

    WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified

    OrtaCVSS 6,9İstismar yokEPSS %1

    bytecodealliance · webassembly micro runtime29 Tem 2025

  • CVE-2026-27195
    27İzleyin

    Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

    OrtaCVSS 6,9İstismar yokEPSS %1

    bytecodealliance · wasmtime24 Şub 2026

  • CVE-2026-34941
    27İzleyin

    Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

    OrtaCVSS 6,9İstismar yokEPSS %0

    bytecodealliance · wasmtime9 Nis 2026