Vulnerabilities (CVE)

Filtered by vendor Webassembly Virtual Machine Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17292 1 Webassembly Virtual Machine Project 1 Webassembly Virtual Machine 2018-11-21 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Denial of Service (application crash caused by out-of-bounds read) by crafting a file that has fewer than 4 bytes.