Vulnerabilities
Vulnerable Software
Webassembly:  Security Vulnerabilities
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Malformed File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
CVSS Score
5.3
EPSS Score
0.005
Published
2025-03-17
WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.
CVSS Score
5.5
EPSS Score
0.002
Published
2023-10-23
WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
CVSS Score
5.5
EPSS Score
0.003
Published
2023-10-23
A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
CVSS Score
6.5
EPSS Score
0.005
Published
2023-08-22
Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.
CVSS Score
6.5
EPSS Score
0.005
Published
2023-08-22
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
CVSS Score
5.5
EPSS Score
0.003
Published
2023-05-23
An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.
CVSS Score
7.5
EPSS Score
0.008
Published
2023-05-23
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
CVSS Score
5.5
EPSS Score
0.003
Published
2023-03-10
WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType.
CVSS Score
5.5
EPSS Score
0.003
Published
2023-03-10
WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
CVSS Score
7.8
EPSS Score
0.003
Published
2023-03-10


Contact Us

Shodan ® - All rights reserved