Vulnerabilities > CVE-2018-17293 - NULL Pointer Dereference vulnerability in Webassembly Virtual Machine Project Webassembly Virtual Machine

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL pointer dereference) or possibly have unspecified other impact by crafting certain WebAssembly files.

Vulnerable Configurations

Part Description Count
Application
Webassembly_Virtual_Machine_Project
102

Common Weakness Enumeration (CWE)