VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

386 CVEsRSS

MAL-2025-49350None
10mo ago

Malicious code in replit_ruspty (crates.io)

Malicious code in replit_ruspty (crates.io)

▾ Sunlitreplit_ruspty · replit_rusptyvia OSV
RUSTSEC-2025-0172None
1y ago

`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead

`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead

▾ Sunlitzip-extract · zip-extractvia OSV
RUSTSEC-2025-0171None
1y ago

soundness issue

soundness issue

▾ Sunlitmod3d-base · mod3d-basevia OSV
RUSTSEC-2025-0170None
1y ago

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

▾ Sunlithugepage-rs · hugepage-rsvia OSV
RUSTSEC-2025-0169None
1y ago

`FormatContext` stream accessors can cause undefined behavior from safe code

`FormatContext` stream accessors can cause undefined behavior from safe code

▾ Sunlitstainless_ffmpeg · stainless_ffmpegvia OSV
CVE-2025-29787High
1y ago

zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write

zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write

▾ Twilightzip · zipEPSS 0.56%via OSV
CVE-2025-5791High· 7.1
1y ago

users: `root` appended to group listings (CVE-2025-5791)

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
RUSTSEC-2024-0401Medium· 5.3
1y ago

Denial of service because of stack overflow with malicious decompression input

Denial of service because of stack overflow with malicious decompression input

▾ Sunlitzlib-rs · zlib-rsvia OSV
RUSTSEC-2024-0404None
2y ago

Unsoundness in anstream

Unsoundness in anstream

▾ Sunlitanstream · anstreamvia OSV
CVE-2024-29640High
2y ago

aliyundrive-webdav vulnerable to Command Injection

aliyundrive-webdav vulnerable to Command Injection

▾ Twilightaliyundrive-webdav · aliyundrive-webdavEPSS 1.2%via OSV
CVE-2024-28854High· 7.5
2y ago

tls-listener affected by the slow loris vulnerability with default configuration

tls-listener affected by the slow loris vulnerability with default configuration

▾ Twilighttls-listener · tls-listenerEPSS 0.96%via OSV
CVE-2024-1410Low· 3.7
2y ago

quiche vulnerable to unbounded storage of information related to connection ID retirement

quiche vulnerable to unbounded storage of information related to connection ID retirement

▾ Sunlitquiche · quicheEPSS 0.66%via OSV
CVE-2024-1765Medium· 5.9
2y ago

quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding

quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding

▾ Sunlitquiche · quicheEPSS 1.2%via OSV
CVE-2021-29511Medium· 6.5
2y ago

Memory over-allocation in evm crate

Memory over-allocation in evm crate

▾ Sunlitevm · evmEPSS 1.3%via OSV
CVE-2023-48795Medium· 5.9PoC
2y ago

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

▾ Twilightrussh · russhEPSS 93%via OSV
CVE-2023-6193Medium· 5.3
2y ago

Unbounded queuing of path validation messages in cloudflare-quiche

Unbounded queuing of path validation messages in cloudflare-quiche

▾ Sunlitquiche · quicheEPSS 0.76%via OSV
CVE-2023-6180Medium· 5.3
2y ago

tokio-boring vulnerable to resource exhaustion via memory leak

tokio-boring vulnerable to resource exhaustion via memory leak

▾ Sunlittokio-boring · tokio-boringEPSS 0.62%via OSV
CVE-2023-49092Medium· 5.9
2y ago

Marvin Attack: potential key recovery through timing sidechannels

Marvin Attack: potential key recovery through timing sidechannels

▾ Sunlitrsa · rsaEPSS 0.61%via OSV
MAL-2023-8429None
2y ago

Malicious code in littest (crates.io)

Malicious code in littest (crates.io)

▾ Sunlitlittest · littestvia OSV
CVE-2023-43669High· 7.5
3y ago

Tungstenite allows remote attackers to cause a denial of service

Tungstenite allows remote attackers to cause a denial of service

▾ Twilighttungstenite · tungsteniteEPSS 2.1%via OSV
RUSTSEC-2023-0085None
3y ago

HPACK decoder panics on invalid input

HPACK decoder panics on invalid input

▾ Sunlithpack · hpackvia OSV
CVE-2023-41880Low· 2.2
3y ago

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

▾ Sunlitwasmtime · wasmtimeEPSS 0.67%via OSV
CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

▾ Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
GHSA-jcr6-4frq-9gjjMedium
3y ago

Users vulnerable to unaligned read of `*const *const c_char` pointer

Users vulnerable to unaligned read of `*const *const c_char` pointer

▾ Sunlitusers · usersvia OSV
CVE-2023-4241High· 7.5
3y ago

lol-html panics on certain HTML inputs

lol-html panics on certain HTML inputs

▾ Twilightlol-html · lol-htmlEPSS 0.69%via OSV
CVE-2023-3766Medium· 5.9
3y ago

odoh-rs's Invalid Slice Split Results in Server Panic

odoh-rs's Invalid Slice Split Results in Server Panic

▾ Sunlitodoh-rs · odoh-rsEPSS 0.78%via OSV
GHSA-mrrw-grhq-86gfMedium
3y ago

Ascii (crate) allows out-of-bounds array indexing in safe code

Ascii (crate) allows out-of-bounds array indexing in safe code

▾ Sunlitascii · asciivia OSV
RUSTSEC-2023-0126None
3y ago

Aliasing violation in `OrdSet` insertion

Aliasing violation in `OrdSet` insertion

▾ Sunlitim · imvia OSV
CVE-2021-21235Medium· 6.5
3y ago

kamadak-exif vulnerable to Infinite loop when parsing PNG files

kamadak-exif vulnerable to Infinite loop when parsing PNG files

▾ Sunlitkamadak-exif · kamadak-exifEPSS 1.5%via OSV
CVE-2021-45707High
4y ago

Out-of-bounds write in nix::unistd::getgrouplist

Out-of-bounds write in nix::unistd::getgrouplist

▾ Twilightnix · nixEPSS 1.7%via OSV
CVEs tagged “rust” — page 12 · VulnSea