Hyper records
12 published records for vendor hyper.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')3
- CWE-190 Integer Overflow or Wraparound2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-254 7PK - Security Features1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
- CWE-772 Missing Release of Resource after Effective Lifetime1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-35863No exploit | An issue was discovered in the hyper crate before 0.12.34 for Rust.hyper · hyper · CWE-444 | Critical9.8 | — | 2.9% | Dec 31, 2020 |
40Plan | CVE-2019-25009No exploit | An issue was discovered in the http crate before 0.1.20 for Rust.hyper · http · CWE-415 | Critical9.8 | — | 1.9% | Dec 31, 2020 |
36Monitor | CVE-2021-32714No exploit | Integer Overflow in Chunked Transfer-Encodinghyper · hyper · CWE-190 | Critical9.1 | — | 1.1% | Jul 7, 2021 |
33Monitor | CVE-2021-21299No exploit | Multiple Transfer-Encoding headers misinterprets request payloadhyper · hyper · CWE-444 | High8.1 | — | 4.8% | Feb 11, 2021 |
31Monitor | CVE-2020-25574No exploit | An issue was discovered in the http crate before 0.1.20 for Rust.hyper · http · CWE-190 | High7.5 | — | 2.5% | Sep 14, 2020 |
31Monitor | CVE-2018-9862No exploit | util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of anhyper · runv · CWE-838 | High7.8 | — | 0.4% | Apr 9, 2018 |
30Monitor | CVE-2023-26964No exploit | An issue was discovered in hyper v0.13.7.hyper · h2 · CWE-770 | High7.5 | — | 1.1% | Apr 11, 2023 |
30Monitor | CVE-2022-31394No exploit | Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing ahyper · hyper · CWE-770 | High7.5 | — | 1.1% | Feb 21, 2023 |
21Monitor | CVE-2018-10205No exploit | hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related tohyper · hyperstart · CWE-772 | Medium5.3 | — | 1.3% | Apr 19, 2018 |
21Monitor | CVE-2017-18587No exploit | An issue was discovered in the hyper crate before 0.9.18 for Rust.hyper · hyper · CWE-93 | Medium5.3 | — | 1.0% | Aug 26, 2019 |
21Monitor | CVE-2021-32715No exploit | Lenient Parsing of Content-Length Header When Prefixed with Plus Signhyper · hyper · CWE-444 | Medium5.3 | — | 1.0% | Jul 7, 2021 |
19Monitor | CVE-2016-10932No exploit | An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows.hyper · hyper · CWE-254 | Medium4.8 | — | 0.7% | Aug 26, 2019 |
- CVE-2020-3586340Plan
An issue was discovered in the hyper crate before 0.12.34 for Rust.
CriticalCVSS 9.8No exploitEPSS 3%hyper · hyperDec 31, 2020
- CVE-2019-2500940Plan
An issue was discovered in the http crate before 0.1.20 for Rust.
CriticalCVSS 9.8No exploitEPSS 2%hyper · httpDec 31, 2020
- CVE-2021-3271436Monitor
Integer Overflow in Chunked Transfer-Encoding
CriticalCVSS 9.1No exploitEPSS 1%hyper · hyperJul 7, 2021
- CVE-2021-2129933Monitor
Multiple Transfer-Encoding headers misinterprets request payload
HighCVSS 8.1No exploitEPSS 5%hyper · hyperFeb 11, 2021
- CVE-2020-2557431Monitor
An issue was discovered in the http crate before 0.1.20 for Rust.
HighCVSS 7.5No exploitEPSS 2%hyper · httpSep 14, 2020
- CVE-2018-986231Monitor
util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an
HighCVSS 7.8No exploitEPSS 0%hyper · runvApr 9, 2018
- CVE-2023-2696430Monitor
An issue was discovered in hyper v0.13.7.
HighCVSS 7.5No exploitEPSS 1%hyper · h2Apr 11, 2023
- CVE-2022-3139430Monitor
Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing a
HighCVSS 7.5No exploitEPSS 1%hyper · hyperFeb 21, 2023
- CVE-2018-1020521Monitor
hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to
MediumCVSS 5.3No exploitEPSS 1%hyper · hyperstartApr 19, 2018
- CVE-2017-1858721Monitor
An issue was discovered in the hyper crate before 0.9.18 for Rust.
MediumCVSS 5.3No exploitEPSS 1%hyper · hyperAug 26, 2019
- CVE-2021-3271521Monitor
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
MediumCVSS 5.3No exploitEPSS 1%hyper · hyperJul 7, 2021
- CVE-2016-1093219Monitor
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows.
MediumCVSS 4.8No exploitEPSS 1%hyper · hyperAug 26, 2019