Skip to main content

Vendor/product archive

rust-lang / rust CVEs

Beta · best-effort

24 CVEs tagged to rust-lang / rust7 Critical, 11 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-43402

Published Sep 4, 2024

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40030

Published Aug 24, 2023

Cargo downloads a Rust project’s dependencies and compiles the project. Starting in Rust 1.60.0 and prior to 1.72, Cargo did not escape Cargo feature names when including them in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29922

Published Aug 7, 2021

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allo…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36323

Published Apr 14, 2021

In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borro…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25008

Published Apr 14, 2021

In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through rac…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20004

Published Apr 14, 2021

In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards can be used across threads with any types, allowing for mem…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28879

Published Apr 11, 2021

In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consum…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-28878

Published Apr 11, 2021

In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (under certain conditions) when next_back(…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28877

Published Apr 11, 2021

In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once when nested. This bug can lead to a memory…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28876

Published Apr 11, 2021

In the standard library in Rust before 1.52.0, the Zip implementation has a panic safety issue. It calls __iterator_get_unchecked() more than once for the same index when the unde…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28875

Published Apr 11, 2021

In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context. This bug could lead to a buffer overflow.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36318

Published Apr 11, 2021

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a us…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36317

Published Apr 11, 2021

In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-20001

Published Apr 11, 2021

In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic elements inside sift_up…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16760

Published Sep 30, 2019

Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1010299

Published Jul 15, 2019

The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000810

Published Oct 8, 2018

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerabi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000657

Published Aug 20, 2018

Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulner…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000622

Published Jul 9, 2018

The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1