lua kayıtları
lua üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-416 Use After Free2
- CWE-787 Out-of-bounds Write2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-15889İstismar yok | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memblua · lua · CWE-125 | Kritik9,8 | — | %2,2 | 21 Tem 2020 |
37İzleyin | CVE-2022-28805İstismar yok | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-basedlua · lua · CWE-125 | Kritik9,1 | — | %3,0 | 8 Nis 2022 |
36İzleyin | CVE-2020-15888İstismar yok | Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-baslua · lua · CWE-125 | Yüksek8,8 | — | %2,4 | 21 Tem 2020 |
35İzleyin | CVE-2019-6706Kavram kanıtı | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.lua · lua · CWE-416 | Yüksek7,5 | — | %17,2 | 23 Oca 2019 |
31İzleyin | CVE-2022-33099İstismar yok | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.lua · lua · CWE-787 | Yüksek7,5 | — | %2,8 | 1 Tem 2022 |
31İzleyin | CVE-2021-32918İstismar yok | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-400 | Yüksek7,5 | — | %2,1 | 13 May 2021 |
31İzleyin | CVE-2020-24369İstismar yok | ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.lua · lua · CWE-476 | Yüksek7,5 | — | %1,7 | 17 Ağu 2020 |
31İzleyin | CVE-2020-24342İstismar yok | Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in alua · lua · CWE-119 | Yüksek7,8 | — | %1,1 | 13 Ağu 2020 |
30İzleyin | CVE-2021-45985İstismar yok | In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.lua · lua · CWE-787 | Yüksek7,5 | — | %1,4 | 10 Nis 2023 |
25İzleyin | CVE-2021-44964İstismar yok | Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a clua · lua · CWE-416 | Orta6,3 | — | %1,0 | 14 Mar 2022 |
24İzleyin | CVE-2014-5461İstismar yok | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial lua · lua · CWE-119 | Orta5,0 | — | %11,7 | 4 Eyl 2014 |
23İzleyin | CVE-2021-32921İstismar yok | An issue was discovered in Prosody before 0.11.9.prosody · prosody · CWE-362 | Orta5,9 | — | %1,6 | 13 May 2021 |
22İzleyin | CVE-2020-24370Kavram kanıtı | ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).lua · lua · CWE-191 | Orta5,3 | — | %3,8 | 17 Ağu 2020 |
22İzleyin | CVE-2020-24371İstismar yok | lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgalua · lua · CWE-763 | Orta5,3 | — | %1,7 | 17 Ağu 2020 |
22İzleyin | CVE-2021-43519İstismar yok | Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script filua · lua · CWE-674 | Orta5,5 | — | %1,2 | 9 Kas 2021 |
22İzleyin | CVE-2020-15945İstismar yok | Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly lua · lua | Orta5,5 | — | %0,5 | 24 Tem 2020 |
22İzleyin | CVE-2021-44647İstismar yok | Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servilua · lua · CWE-843 | Orta5,5 | — | %0,4 | 11 Oca 2022 |
- CVE-2020-1588940Planlayın
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list memb
KritikCVSS 9,8İstismar yokEPSS %2lua · lua21 Tem 2020
- CVE-2022-2880537İzleyin
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based
KritikCVSS 9,1İstismar yokEPSS %3lua · lua8 Nis 2022
- CVE-2020-1588836İzleyin
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-bas
YüksekCVSS 8,8İstismar yokEPSS %2lua · lua21 Tem 2020
- CVE-2019-670635İzleyin
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c.
YüksekCVSS 7,5Kavram kanıtıEPSS %17lua · lua23 Oca 2019
- CVE-2022-3309931İzleyin
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
YüksekCVSS 7,5İstismar yokEPSS %3lua · lua1 Tem 2022
- CVE-2021-3291831İzleyin
An issue was discovered in Prosody before 0.11.9.
YüksekCVSS 7,5İstismar yokEPSS %2prosody · prosody13 May 2021
- CVE-2020-2436931İzleyin
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
YüksekCVSS 7,5İstismar yokEPSS %2lua · lua17 Ağu 2020
- CVE-2020-2434231İzleyin
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a
YüksekCVSS 7,8İstismar yokEPSS %1lua · lua13 Ağu 2020
- CVE-2021-4598530İzleyin
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
YüksekCVSS 7,5İstismar yokEPSS %1lua · lua10 Nis 2023
- CVE-2021-4496425İzleyin
Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a c
OrtaCVSS 6,3İstismar yokEPSS %1lua · lua14 Mar 2022
- CVE-2014-546124İzleyin
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
OrtaCVSS 5,0İstismar yokEPSS %12lua · lua4 Eyl 2014
- CVE-2021-3292123İzleyin
An issue was discovered in Prosody before 0.11.9.
OrtaCVSS 5,9İstismar yokEPSS %2prosody · prosody13 May 2021
- CVE-2020-2437022İzleyin
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
OrtaCVSS 5,3Kavram kanıtıEPSS %4lua · lua17 Ağu 2020
- CVE-2020-2437122İzleyin
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectga
OrtaCVSS 5,3İstismar yokEPSS %2lua · lua17 Ağu 2020
- CVE-2021-4351922İzleyin
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script fi
OrtaCVSS 5,5İstismar yokEPSS %1lua · lua9 Kas 2021
- CVE-2020-1594522İzleyin
Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly
OrtaCVSS 5,5İstismar yokEPSS %1lua · lua24 Tem 2020
- CVE-2021-4464722İzleyin
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of servi
OrtaCVSS 5,5İstismar yokEPSS %0lua · lua11 Oca 2022