Vulnerabilities > Bytecodealliance > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-48105 Out-of-bounds Write vulnerability in Bytecodealliance Webassembly Micro Runtime 1.2.3
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
network
low complexity
bytecodealliance CWE-787
7.5
2023-04-27 CVE-2023-30624 Reliance on Undefined, Unspecified, or Implementation-Defined Behavior vulnerability in Bytecodealliance Wasmtime
Wasmtime is a standalone runtime for WebAssembly.
network
low complexity
bytecodealliance CWE-758
8.8
2022-11-10 CVE-2022-39392 Out-of-bounds Write vulnerability in Bytecodealliance Wasmtime
Wasmtime is a standalone runtime for WebAssembly.
network
high complexity
bytecodealliance CWE-787
7.4
2022-11-10 CVE-2022-39393 Improper Cross-boundary Removal of Sensitive Data vulnerability in Bytecodealliance Wasmtime
Wasmtime is a standalone runtime for WebAssembly.
network
low complexity
bytecodealliance CWE-212
8.6
2022-02-16 CVE-2022-23636 Access of Uninitialized Pointer vulnerability in Bytecodealliance Wasmtime
Wasmtime is an open source runtime for WebAssembly & WASI.
7.1
2021-05-24 CVE-2021-32629 Access of Memory Location After End of Buffer vulnerability in Bytecodealliance Cranelift-Codegen
Cranelift is an open-source code generator maintained by Bytecode Alliance.
local
low complexity
bytecodealliance CWE-788
8.8