Skip to main content

Vendor archive

rust-lang CVEs

Beta · best-effort

39 CVEs tagged to vendor rust-lang7 Critical, 15 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2020-36202

Published Jan 26, 2021

An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26297

Published Jan 4, 2021

mdBook is a utility to create modern online books from Markdown files and is written in Rust. In mdBook before version 0.4.5, there is a vulnerability affecting the search feature…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35920

Published Dec 31, 2020

An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35908

Published Dec 31, 2020

An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35907

Published Dec 31, 2020

An issue was discovered in the futures-task crate before 0.3.5 for Rust. futures_task::noop_waker_ref allows a NULL pointer dereference.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35906

Published Dec 31, 2020

An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35905

Published Dec 31, 2020

An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code).

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26281

Published Dec 21, 2020

async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webse…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16760

Published Sep 30, 2019

Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1010299

Published Jul 15, 2019

The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000810

Published Oct 8, 2018

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerabi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000657

Published Aug 20, 2018

Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulner…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000622

Published Jul 9, 2018

The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-39 of 39 CVEsPage 2 of 2