Rust-Lang / Rust
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-43402 | Rust OS Command Injection/Argument Injection vulnerability | HIGH | 8.8 | Sep 4, 2024 |
| CVE-2024-3566 | Command injection vulnerability in programing languages on Microsoft Windows operating system. | CRITICAL | 9.8 | Apr 10, 2024 |
| CVE-2024-24576 | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows | CRITICAL | 10.0 | Apr 9, 2024 |
| CVE-2023-40030 | Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports | MEDIUM | 6.1 | Aug 24, 2023 |
| CVE-2022-21658 | Race condition in std::fs::remove_dir_all in rustlang | HIGH | 7.3 | Jan 20, 2022 |
| CVE-2021-29922 | rust: incorrect parsing of extraneous zero characters at the beginning of an IP address string | CRITICAL | 9.1 | Aug 7, 2021 |
| CVE-2017-20004 | rust: synchronization problem in the MutexGuard object | MEDIUM | 5.9 | Apr 14, 2021 |
| CVE-2020-36323 | rust: optimization for joining strings can cause uninitialized bytes to be exposed | HIGH | 8.2 | Apr 14, 2021 |
| CVE-2018-25008 | rust: weak synchronization in the Arc::get_mut method | MEDIUM | 5.9 | Apr 14, 2021 |
| CVE-2021-31162 | rust: double free in Vec::from_iter function if freeing the element panics | CRITICAL | 9.8 | Apr 14, 2021 |
| CVE-2015-20001 | In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic ele… | HIGH | 7.5 | Apr 11, 2021 |
| CVE-2020-36317 | rust: memory safety violation in String::retain() | HIGH | 7.5 | Apr 11, 2021 |
| CVE-2020-36318 | rust: use-after-free or double free in VecDeque::make_contiguous | CRITICAL | 9.8 | Apr 11, 2021 |
| CVE-2021-28879 | rust: integer overflow in the Zip implementation can lead to a buffer overflow | CRITICAL | 9.8 | Apr 11, 2021 |
| CVE-2021-28878 | rust: memory safety violation in Zip implementation when next_back() and next() are used together | HIGH | 7.5 | Apr 11, 2021 |
| CVE-2021-28877 | rust: memory safety violation in Zip implementation for nested iter::Zips | HIGH | 7.5 | Apr 11, 2021 |
| CVE-2021-28876 | rust: panic safety issue in Zip implementation | MEDIUM | 5.3 | Apr 11, 2021 |
| CVE-2021-28875 | rust: heap-based buffer overflow in read_to_end() because it does not validate the return value from Read in an unsafe context | HIGH | 7.5 | Apr 11, 2021 |
| CVE-2019-16760 | Cargo prior to Rust 1.26.0 may download the wrong dependency | HIGH | 7.5 | Sep 30, 2019 |
| CVE-2019-1010299 | rust: print of uninitialized memory in the debug trait implementation for std::collections::vec_deque::Iter | MEDIUM | 5.3 | Jul 15, 2019 |
| CVE-2019-12083 | The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and… | HIGH | 8.1 | May 13, 2019 |
| CVE-2018-1000810 | rust: Buffer overflow in str::repeat function in the standard library | CRITICAL | 9.8 | Oct 8, 2018 |
| CVE-2018-1000657 | rust: Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function | HIGH | 7.8 | Aug 20, 2018 |
| CVE-2018-1000622 | rust: rustdoc loads plugins from world writable directory allowing for arbitrary code execution | HIGH | 7.8 | Jul 9, 2018 |
Showing 1 to 24 of 24 CVEs