Alex Crichton
18 exploits
Active since Sep 2021
Wasmtime 39.0.0-40.0.3 - Denial of Service via Async Component Function Call Panic
CVSS 7.5
tar-rs incorrectly ignores PAX size headers if header size is nonzero
CVSS 8.1
tar-rs: unpack_in can chmod arbitrary directories by following symlinks
CVSS 6.5
Wasmtime 39.0.0-40.0.3 - Denial of Service via Async Component Function Call Panic
CVSS 7.5
Wasmtime <24.0.6/36.0.6/4.0.04/41.0.4/42.0.0 - DoS
CVSS 7.5
Wasmtime < 0.30.0 - Type Confusion via Cross-Engine Linker Usage
CVSS 6.3
Lucet < 0.6.1 - Use-After-Free in Instance Object
CVSS 8.5
Wasmtime < 1.0.2 and 2.0.0-2.0.2 - Memory Corruption via Pooling Instance Allocator Misconfiguration
CVSS 5.9
Wasmtime <2.0.2, <1.0.2 - Info Disclosure
CVSS 8.6
Wasmtime <1.0.2 and 2.0.0-2.0.1 - Out-of-bounds Write in C API wasmtime_trap_code
CVSS 3.8
Cranelift Codegen 0.84.0-0.91.1 and Wasmtime 0.37.0-4.0.1 - Out-of-bounds Read via x86_64 Address Mode Calculation
CVSS 9.9
wasmtime 4.0.1-6.0.1 and cranelift-codegen 0.84.0-0.91.1 - Off-by-one Error in i8x16.select Instruction
CVSS 3.1
Wasmtime <6.0.2-8.0.1 - Buffer Overflow
CVSS 3.9
Wasmtime 10.0.0-10.0.2, 11.0.0-11.0.2, 12.0.0-12.0.1 - Incorrect Result via i64x2.shr_s Miscompilation
CVSS 2.2
wasmtime 19.0.0 - Type Confusion via WebAssembly Module Execution
CVSS 3.3
Wasmtime 37.0.0-37.0.1 - Memory Leak in C/C++ API via anyref and externref Handling
CVSS 3.3
Wasmtime 38.0.0-38.0.2 - Denial of Service via Crafted Component-Model Trampoline
CVSS 3.1
Wasmtime 24.0.0-24.0.4, 26.0.0-36.0.2, 37.0.0-37.0.2, 38.0.0-38.0.3 - Data Race via Shared Linear Memory
CVSS 1.8