Search CVE reports
201 – 210 of 37963 results
Not in release
Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the f64x2.splat WebAssembly instruction with Cranelift may load 8 more bytes than...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic which can happen when a flags-typed component model value is lifted with the Val type. If bits are set outside...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 or latin1+utf16 encodings improperly verified the alignment of...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would...
1 affected package
rust-wasmtime
| Package | 22.04 LTS |
|---|---|
| rust-wasmtime | Not in release |
Not in release
basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(),...
1 affected package
node-proxy-agents
| Package | 22.04 LTS |
|---|---|
| node-proxy-agents | Not in release |
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can...
1 affected package
gnutls28
| Package | 22.04 LTS |
|---|---|
| gnutls28 | Not affected |