Vulnerabilities > CVE-2018-17293 - NULL Pointer Dereference vulnerability in Webassembly Virtual Machine Project Webassembly Virtual Machine

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL pointer dereference) or possibly have unspecified other impact by crafting certain WebAssembly files.

Vulnerable Configurations

Part Description Count
Application
Webassembly_Virtual_Machine_Project
102

Common Weakness Enumeration (CWE)