Vulnerabilities (CVE)

Filtered by vendor Webassembly Subscribe
Filtered by product Wabt
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2584 1 Webassembly 1 Wabt 2025-03-24 5.1 MEDIUM 5.0 MEDIUM
A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVE-2023-27119 1 Webassembly 1 Wabt 2025-02-28 N/A 5.5 MEDIUM
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
CVE-2022-43283 1 Webassembly 1 Wabt 2024-11-21 N/A 5.5 MEDIUM
wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.
CVE-2022-43282 1 Webassembly 1 Wabt 2024-11-21 N/A 7.1 HIGH
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.
CVE-2022-43280 1 Webassembly 1 Wabt 2024-11-21 N/A 7.1 HIGH
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.