Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-45946: oss-fuzz-vulns/OSV-2021-678.yaml at main · google/oss-fuzz-vulns

Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements).

CVE
#google#git

Permalink

Cannot retrieve contributors at this time

id: OSV-2021-678

summary: UNKNOWN WRITE in CompileBlock

details: |

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33555

Crash type: UNKNOWN WRITE

Crash state:

CompileBlock

Compile_LoopOrBlock

CompileBlockStatements

modified: ‘2021-04-23T00:00:13.901043Z’

published: ‘2021-04-23T00:00:13.900793Z’

references:

- type: REPORT

url: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=33555

affected:

- package:

name: wasm3

ecosystem: OSS-Fuzz

ranges:

- type: GIT

repo: https://github.com/wasm3/wasm3

events:

- introduced: ef7c7f3a7578b9ed362cfbd0d1c6f065678df531

versions:

- v0.5.0

ecosystem_specific:

severity: HIGH

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907