bytecodealliance kayıtları
bytecodealliance üreticisine ait 55 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %85,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read8
- CWE-416 Use After Free5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-787 Out-of-bounds Write3
- CWE-193 Off-by-one Error2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
55 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-26489İstismar yok | Guest-controlled out-of-bounds read/write on x86_64 in wasmtimebytecodealliance · cranelift-codegen · CWE-125 | Kritik9,9 | — | %1,3 | 8 Mar 2023 |
39İzleyin | CVE-2022-24791İstismar yok | Use after free in Wasmtimebytecodealliance · wasmtime · CWE-416 | Kritik9,8 | — | %1,2 | 31 Mar 2022 |
39İzleyin | CVE-2022-39394İstismar yok | wasmtime_trap_code C API function has out of bounds write vulnerabilitybytecodealliance · wasmtime · CWE-787 | Kritik9,8 | — | %0,3 | 10 Kas 2022 |
36İzleyin | CVE-2026-34987İstismar yok | Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessbytecodealliance · wasmtime · CWE-125 | Kritik9,0 | — | %0,5 | 9 Nis 2026 |
36İzleyin | CVE-2026-34971İstismar yok | Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Craneliftbytecodealliance · wasmtime · CWE-125 | Kritik9,0 | — | %0,4 | 9 Nis 2026 |
35İzleyin | CVE-2022-31146İstismar yok | Use After Free in Wasmtimebytecodealliance · cranelift-codegen · CWE-416 | Yüksek8,8 | — | %1,2 | 21 Tem 2022 |
35İzleyin | CVE-2021-32629İstismar yok | Memory access due to code generation flaw in Cranelift modulebytecodealliance · cranelift-codegen · CWE-788 | Yüksek8,8 | — | %0,5 | 24 May 2021 |
35İzleyin | CVE-2023-30624İstismar yok | Wasmtime has Undefined Behavior in Rust runtime functionsbytecodealliance · wasmtime · CWE-758 | Yüksek8,8 | — | %0,5 | 27 Nis 2023 |
34İzleyin | CVE-2022-39393İstismar yok | Wasmtime vulnerable to data leakage between instances in the pooling allocatorbytecodealliance · wasmtime · CWE-226 | Yüksek8,6 | — | %0,7 | 10 Kas 2022 |
32İzleyin | CVE-2021-43790İstismar yok | Use After Free in lucetbytecodealliance · lucet · CWE-416 | Yüksek8,1 | — | %1,6 | 29 Kas 2021 |
32İzleyin | CVE-2022-23636Kavram kanıtı | Invalid drop of partially-initialized instances in wasmtimebytecodealliance · wasmtime · CWE-824 | Yüksek8,1 | — | %0,8 | 16 Şub 2022 |
31İzleyin | CVE-2024-25431İstismar yok | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privilegesbytecodealliance · webassembly micro runtime · CWE-125 | Yüksek7,8 | — | %0,6 | 8 Kas 2024 |
30İzleyin | CVE-2023-48105İstismar yok | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of bytecodealliance · webassembly micro runtime · CWE-787 | Yüksek7,5 | — | %1,0 | 22 Kas 2023 |
30İzleyin | CVE-2022-31169İstismar yok | Cranelift vulnerable to miscompilation of constant values in division on AArch64bytecodealliance · cranelift-codegen · CWE-682 | Yüksek7,5 | — | %0,9 | 22 Tem 2022 |
30İzleyin | CVE-2024-34251İstismar yok | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cabytecodealliance · webassembly micro runtime · CWE-125 | Yüksek7,5 | — | %0,8 | 6 May 2024 |
30İzleyin | CVE-2024-27532İstismar yok | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_resbytecodealliance · webassembly micro runtime · CWE-476 | Yüksek7,5 | — | %0,5 | 8 Kas 2024 |
30İzleyin | CVE-2026-47261İstismar yok | Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionbytecodealliance · wasmtime · CWE-284 | Yüksek7,5 | — | %0,5 | 15 Haz 2026 |
29İzleyin | CVE-2022-39392İstismar yok | Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configurationbytecodealliance · wasmtime · CWE-119 | Yüksek7,4 | — | %0,6 | 10 Kas 2022 |
29İzleyin | CVE-2025-64713İstismar yok | WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcodebytecodealliance · webassembly micro runtime · CWE-119 | Yüksek7,4 | — | %0,3 | 25 Kas 2025 |
28İzleyin | CVE-2025-43853İstismar yok | iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi featurebytecodealliance · webassembly micro runtime · CWE-61 | Yüksek7,0 | — | %0,3 | 15 May 2025 |
27İzleyin | CVE-2026-27572İstismar yok | Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instancebytecodealliance · wasmtime · CWE-770 | Orta6,9 | — | %0,7 | 24 Şub 2026 |
27İzleyin | CVE-2026-27204İstismar yok | Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionbytecodealliance · wasmtime · CWE-400 | Orta6,9 | — | %0,7 | 24 Şub 2026 |
27İzleyin | CVE-2025-54126İstismar yok | WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specifiedbytecodealliance · webassembly micro runtime · CWE-668 | Orta6,9 | — | %0,6 | 29 Tem 2025 |
27İzleyin | CVE-2026-27195İstismar yok | Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` futurebytecodealliance · wasmtime · CWE-755 | Orta6,9 | — | %0,6 | 24 Şub 2026 |
27İzleyin | CVE-2026-34941İstismar yok | Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingbytecodealliance · wasmtime · CWE-125 | Orta6,9 | — | %0,5 | 9 Nis 2026 |
- CVE-2023-2648939İzleyin
Guest-controlled out-of-bounds read/write on x86_64 in wasmtime
KritikCVSS 9,9İstismar yokEPSS %1bytecodealliance · cranelift-codegen8 Mar 2023
- CVE-2022-2479139İzleyin
Use after free in Wasmtime
KritikCVSS 9,8İstismar yokEPSS %1bytecodealliance · wasmtime31 Mar 2022
- CVE-2022-3939439İzleyin
wasmtime_trap_code C API function has out of bounds write vulnerability
KritikCVSS 9,8İstismar yokEPSS %0bytecodealliance · wasmtime10 Kas 2022
- CVE-2026-3498736İzleyin
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
KritikCVSS 9,0İstismar yokEPSS %0bytecodealliance · wasmtime9 Nis 2026
- CVE-2026-3497136İzleyin
Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
KritikCVSS 9,0İstismar yokEPSS %0bytecodealliance · wasmtime9 Nis 2026
- CVE-2022-3114635İzleyin
Use After Free in Wasmtime
YüksekCVSS 8,8İstismar yokEPSS %1bytecodealliance · cranelift-codegen21 Tem 2022
- CVE-2021-3262935İzleyin
Memory access due to code generation flaw in Cranelift module
YüksekCVSS 8,8İstismar yokEPSS %0bytecodealliance · cranelift-codegen24 May 2021
- CVE-2023-3062435İzleyin
Wasmtime has Undefined Behavior in Rust runtime functions
YüksekCVSS 8,8İstismar yokEPSS %0bytecodealliance · wasmtime27 Nis 2023
- CVE-2022-3939334İzleyin
Wasmtime vulnerable to data leakage between instances in the pooling allocator
YüksekCVSS 8,6İstismar yokEPSS %1bytecodealliance · wasmtime10 Kas 2022
- CVE-2021-4379032İzleyin
Use After Free in lucet
YüksekCVSS 8,1İstismar yokEPSS %2bytecodealliance · lucet29 Kas 2021
- CVE-2022-2363632İzleyin
Invalid drop of partially-initialized instances in wasmtime
YüksekCVSS 8,1Kavram kanıtıEPSS %1bytecodealliance · wasmtime16 Şub 2022
- CVE-2024-2543131İzleyin
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges
YüksekCVSS 7,8İstismar yokEPSS %1bytecodealliance · webassembly micro runtime8 Kas 2024
- CVE-2023-4810530İzleyin
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of
YüksekCVSS 7,5İstismar yokEPSS %1bytecodealliance · webassembly micro runtime22 Kas 2023
- CVE-2022-3116930İzleyin
Cranelift vulnerable to miscompilation of constant values in division on AArch64
YüksekCVSS 7,5İstismar yokEPSS %1bytecodealliance · cranelift-codegen22 Tem 2022
- CVE-2024-3425130İzleyin
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to ca
YüksekCVSS 7,5İstismar yokEPSS %1bytecodealliance · webassembly micro runtime6 May 2024
- CVE-2024-2753230İzleyin
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_res
YüksekCVSS 7,5İstismar yokEPSS %1bytecodealliance · webassembly micro runtime8 Kas 2024
- CVE-2026-4726130İzleyin
Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
YüksekCVSS 7,5İstismar yokEPSS %1bytecodealliance · wasmtime15 Haz 2026
- CVE-2022-3939229İzleyin
Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configuration
YüksekCVSS 7,4İstismar yokEPSS %1bytecodealliance · wasmtime10 Kas 2022
- CVE-2025-6471329İzleyin
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
YüksekCVSS 7,4İstismar yokEPSS %0bytecodealliance · webassembly micro runtime25 Kas 2025
- CVE-2025-4385328İzleyin
iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
YüksekCVSS 7,0İstismar yokEPSS %0bytecodealliance · webassembly micro runtime15 May 2025
- CVE-2026-2757227İzleyin
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
OrtaCVSS 6,9İstismar yokEPSS %1bytecodealliance · wasmtime24 Şub 2026
- CVE-2026-2720427İzleyin
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
OrtaCVSS 6,9İstismar yokEPSS %1bytecodealliance · wasmtime24 Şub 2026
- CVE-2025-5412627İzleyin
WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
OrtaCVSS 6,9İstismar yokEPSS %1bytecodealliance · webassembly micro runtime29 Tem 2025
- CVE-2026-2719527İzleyin
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
OrtaCVSS 6,9İstismar yokEPSS %1bytecodealliance · wasmtime24 Şub 2026
- CVE-2026-3494127İzleyin
Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
OrtaCVSS 6,9İstismar yokEPSS %0bytecodealliance · wasmtime9 Nis 2026