CVE-2026-90648
- EPSS 0.15%
- Veröffentlicht 12.09.2026 23:16:34
- Zuletzt bearbeitet 22.09.2026 20:00:03
wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-...
CVE-2025-15412
- EPSS 0.19%
- Veröffentlicht 01.01.2026 20:32:06
- Zuletzt bearbeitet 07.10.2026 11:10:00
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-b...
CVE-2025-15411
- EPSS 0.19%
- Veröffentlicht 01.01.2026 19:32:07
- Zuletzt bearbeitet 07.10.2026 11:10:00
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption....
CVE-2025-6275
- EPSS 0.21%
- Veröffentlicht 19.06.2025 19:31:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It...
CVE-2025-6274
- EPSS 0.2%
- Veröffentlicht 19.06.2025 19:00:16
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally ...
CVE-2025-6273
- EPSS 0.2%
- Veröffentlicht 19.06.2025 18:31:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion. Local access is required to a...
CVE-2025-3122
- EPSS 0.57%
- Veröffentlicht 02.04.2025 22:15:21
- Zuletzt bearbeitet 23.09.2025 16:54:41
A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointe...
CVE-2025-2584
- EPSS 0.5%
- Veröffentlicht 21.03.2025 07:31:03
- Zuletzt bearbeitet 25.11.2025 19:43:01
A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads...
CVE-2025-2368
- EPSS 0.57%
- Veröffentlicht 17.03.2025 08:00:05
- Zuletzt bearbeitet 06.01.2026 16:29:46
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Ma...
CVE-2023-27119
- EPSS 0.28%
- Veröffentlicht 10.03.2023 02:15:58
- Zuletzt bearbeitet 28.02.2025 22:15:38
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.