Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wenyongh

#18808of 53,630
14.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-20939
8.8
2024-11-08
Bytecode Alliance · Wasm-Micro-Runtime · CVE-2024-25431
**Name of the Vulnerable Software and Affected Versions** bytecodealliance wasm-micro-runtime versions before v.b3f728c **Description** The issue allows a remote attacker to escalate privileges via a crafted file to the `check was abi compatibility` function. **Recommendations** For versions before v.b3f728c, update to a version that includes the fix from commit 06df58f to resolve the issue. As a temporary workaround, consider restricting access to the `check was abi compatibility` function until a patch is available.
PT-2023-31956
5.5
2023-12-30
Bytecode Alliance · Wasm-Micro-Runtime · CVE-2023-52284
**Name of the Vulnerable Software and Affected Versions** Bytecode Alliance wasm-micro-runtime versions prior to 1.3.0 **Description** The issue arises from the mishandling of `push pop frame ref offset`, leading to a "double free or corruption" error for a valid WebAssembly module. **Recommendations** For versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue.