Vulnerabilities
Vulnerable Software
Lua:  >> Lua  >> 5.4.3  Security Vulnerabilities
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-04-10
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-07-01
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
CVSS Score
9.1
EPSS Score
0.001
Published
2022-04-08
Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.
CVSS Score
6.3
EPSS Score
0.001
Published
2022-03-14
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-01-11
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-11-09
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
CVSS Score
5.9
EPSS Score
0.032
Published
2021-05-13


Contact Us

Shodan ® - All rights reserved