Tagged “rust”
CVEs tagged rust, newest first.
390 CVEsRSS
RUSTSEC-2023-0126NoneAliasing violation in `OrdSet` insertion
Aliasing violation in `OrdSet` insertion
CVE-2021-21235Medium· 6.5kamadak-exif vulnerable to Infinite loop when parsing PNG files
kamadak-exif vulnerable to Infinite loop when parsing PNG files
CVE-2021-45707HighOut-of-bounds write in nix::unistd::getgrouplist
Out-of-bounds write in nix::unistd::getgrouplist
CVE-2020-36846Medium· 6.5Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
CVE-2022-23639NoneUnsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64
Unsoundness of AtomicCell<*64> arithmetics on 32-bit targets that support Atomic*64
CVE-2021-43790High· 8.5Use After Free in lucet
Use After Free in lucet
CVE-2021-41149High· 8.2Improper sanitization of target names
Improper sanitization of target names
CVE-2021-41138Medium· 5.3Validity check missing in Frontier
Validity check missing in Frontier
CVE-2021-32619Critical· 9.8Deno's static imports inside dynamically imported modules do not adhere to permission checks
Deno's static imports inside dynamically imported modules do not adhere to permission checks
CVE-2021-39228Medium· 6.5Memory Safety Issue when using patch or merge on state and assign the result back to state
Memory Safety Issue when using patch or merge on state and assign the result back to state
CVE-2021-39216Medium· 6.3Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
CVE-2021-39193Medium· 5.3Transaction validity oversight in pallet-ethereum
Transaction validity oversight in pallet-ethereum
CVE-2021-29937Critical· 9.8Free of uninitialized memory in telemetry
Free of uninitialized memory in telemetry
CVE-2020-15254High· 8.1crossbeam-channel Undefined Behavior before v0.4.4
crossbeam-channel Undefined Behavior before v0.4.4
CVE-2021-32810Critical· 9.8crossbeam-deque Data Race before v0.7.4 and v0.8.1
crossbeam-deque Data Race before v0.7.4 and v0.8.1
CVE-2021-21299Medium· 4.8HTTP Request Smuggling in hyper
HTTP Request Smuggling in hyper
CVE-2020-15093High· 8.6Improper verification of signature threshold in tough
Improper verification of signature threshold in tough
CVE-2021-32629High· 7.2Memory access due to code generation flaw in Cranelift module
Memory access due to code generation flaw in Cranelift module
CVE-2021-38511High· 7.5Links in archive can create arbitrary directories
Links in archive can create arbitrary directories
CVE-2021-32715Low· 3.1Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
CVE-2021-32714Medium· 5.9Integer Overflow in Chunked Transfer-Encoding
Integer Overflow in Chunked Transfer-Encoding
RUSTSEC-2021-0156NoneTriton VM Soundness Vulnerability due to Missing Constraint
Triton VM Soundness Vulnerability due to Missing Constraint
CVE-2021-25900Critical· 9.8Buffer overflow in SmallVec::insert_many
Buffer overflow in SmallVec::insert_many
RUSTSEC-2020-0164None`cell-project` used incorrect variance when projecting through `&Cell<T>`
`cell-project` used incorrect variance when projecting through `&Cell<T>`
CVE-2020-35858Critical· 9.8Parsing a specially crafted message can result in a stack overflow
Parsing a specially crafted message can result in a stack overflow
CVE-2019-15554Critical· 9.8Memory corruption in SmallVec::grow()
Memory corruption in SmallVec::grow()
CVE-2019-15551Critical· 9.8Double-free and use-after-free in SmallVec::grow()
Double-free and use-after-free in SmallVec::grow()
CVE-2018-20998Critical· 9.8Enum repr causing potential memory corruption
Enum repr causing potential memory corruption
CVE-2018-20996Critical· 9.8MsQueue and SegQueue suffer from double-free
MsQueue and SegQueue suffer from double-free
CVE-2018-20991Critical· 9.8Possible double free during unwinding in SmallVec::insert_many
Possible double free during unwinding in SmallVec::insert_many