Vulnerabilities (CVE)

Filtered by vendor Webassembly
Angry Yack Logo
Total 44 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-14957 1 Webassembly 1 Binaryen 2026-02-24 1.7 LOW 3.3 LOW
A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such manipulation of the argument Index leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 6fb2b917a79578ab44cf3b900a6da4c27251e0d4. Applying a patch is ad ...

Show More

CVE-2025-14956 1 Webassembly 1 Binaryen 2026-02-24 4.3 MEDIUM 5.3 MEDIUM
A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: 4f52bff8c4075b5630422f902dd92a0af2c9f398. It is recommended to apply a patch to fix this issue.
CVE-2025-15412 1 Webassembly 1 Wabt 2026-02-23 4.3 MEDIUM 5.3 MEDIUM
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the resea ...

Show More

CVE-2025-15411 1 Webassembly 1 Wabt 2026-02-23 4.3 MEDIUM 5.3 MEDIUM
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recomm ...

Show More

CVE-2025-2368 1 Webassembly 1 Wabt 2026-01-06 7.5 HIGH 6.3 MEDIUM
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Malformed File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
CVE-2025-6273 1 Webassembly 1 Wabt 2026-01-06 1.7 LOW 3.3 LOW
A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains that this issue might not affect "real world wasm programs".
CVE-2025-2584 1 Webassembly 1 Wabt 2025-11-25 5.1 MEDIUM 5.0 MEDIUM
A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVE-2025-3122 1 Webassembly 1 Webassembly Binary Toolkit 2025-09-23 2.6 LOW 3.1 LOW
A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVE-2025-6275 1 Webassembly 1 Wabt 2025-07-02 1.7 LOW 3.3 LOW
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm pro ...

Show More

CVE-2025-6274 1 Webassembly 1 Wabt 2025-07-02 1.7 LOW 3.3 LOW
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might ...

Show More

CVE-2022-43283 1 Webassembly 1 Wabt 2025-05-08 N/A 5.5 MEDIUM
wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.
CVE-2022-43282 1 Webassembly 1 Wabt 2025-05-08 N/A 7.1 HIGH
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.
CVE-2022-43281 1 Webassembly 1 Wasm 2025-05-08 N/A 7.8 HIGH
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.
CVE-2022-43280 1 Webassembly 1 Wabt 2025-05-07 N/A 7.1 HIGH
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
CVE-2023-27119 1 Webassembly 1 Wabt 2025-02-28 N/A 5.5 MEDIUM
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
CVE-2023-27115 1 Webassembly 1 Webassembly 2025-02-28 N/A 5.5 MEDIUM
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
CVE-2023-31670 1 Webassembly 1 Webassembly Binary Toolkit 2025-01-31 N/A 7.5 HIGH
An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.
CVE-2023-31669 1 Webassembly 1 Webassembly Binary Toolkit 2025-01-31 N/A 5.5 MEDIUM
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
CVE-2023-46332 1 Webassembly 1 Webassembly Binary Toolkit 2024-11-21 N/A 5.5 MEDIUM
WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
CVE-2023-46331 1 Webassembly 1 Webassembly Binary Toolkit 2024-11-21 N/A 5.5 MEDIUM
WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.
CVE-2023-27117 1 Webassembly 1 Webassembly 2024-11-21 N/A 7.8 HIGH
WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
CVE-2023-27116 1 Webassembly 1 Webassembly 2024-11-21 N/A 5.5 MEDIUM
WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType.
CVE-2021-46055 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
CVE-2021-46054 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
CVE-2021-46053 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Denial of Service vulnerability exists in Binaryen 103. The program terminates with signal SIGKILL.
CVE-2021-46052 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.
CVE-2021-46050 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function.
CVE-2021-46048 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.
CVE-2021-45293 2 Fedoraproject, Webassembly 2 Fedora, Binaryen 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.
CVE-2021-45290 2 Fedoraproject, Webassembly 2 Fedora, Binaryen 2024-11-21 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
CVE-2020-18382 1 Webassembly 1 Binaryen 2024-11-21 N/A 6.5 MEDIUM
Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.
CVE-2020-18378 1 Webassembly 1 Binaryen 2024-11-21 N/A 6.5 MEDIUM
A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
CVE-2019-7704 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.
CVE-2019-7703 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
In Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service via a wasm file, as demonstrated by wasm-merge.
CVE-2019-7702 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A NULL pointer dereference was discovered in wasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
CVE-2019-7701 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm2js.
CVE-2019-7700 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.
CVE-2019-7662 1 Webassembly 1 Binaryen 2024-11-21 7.1 HIGH 6.5 MEDIUM
An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This allows remote attackers to cause a denial of service (failed assertion and crash) via a crafted wasm file.
CVE-2019-7154 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.
CVE-2019-7153 1 Webassembly 1 Binaryen 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.