CVE-2024-25176
- EPSS 0.08%
- Veröffentlicht 07.07.2025 00:00:00
- Zuletzt bearbeitet 24.07.2025 16:15:30
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
CVE-2024-25177
- EPSS 0.11%
- Veröffentlicht 07.07.2025 00:00:00
- Zuletzt bearbeitet 24.07.2025 16:15:30
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
CVE-2024-25178
- EPSS 0.08%
- Veröffentlicht 07.07.2025 00:00:00
- Zuletzt bearbeitet 24.07.2025 16:15:30
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
CVE-2020-24372
- EPSS 0.32%
- Veröffentlicht 17.08.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:14:41
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
CVE-2020-15890
- EPSS 0.98%
- Veröffentlicht 21.07.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:23
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
CVE-2019-19391
- EPSS 0.27%
- Veröffentlicht 29.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:42
In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, because certain cases involving valid stack levels and > options are mishan...