Skip to content
Noroxi

rust-lang records

39 published records for vendor rust-lang.

All records

39 records
  • Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows

    CriticalCVSS 10.0Proof of conceptEPSS 20%

    fedoraproject · fedoraApr 9, 2024

  • Command injection vulnerability in programing languages on Microsoft Windows operating system.

    CriticalCVSS 9.8No exploitEPSS 7%

    haskell · process libraryApr 10, 2024

  • The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Intege

    CriticalCVSS 9.8No exploitEPSS 3%

    rust-lang · rustOct 8, 2018

  • In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.

    CriticalCVSS 9.8No exploitEPSS 3%

    rust-lang · rustApr 14, 2021

  • In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.

    CriticalCVSS 9.8No exploitEPSS 2%

    rust-lang · rustApr 11, 2021

  • In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain c

    CriticalCVSS 9.8No exploitEPSS 2%

    rust-lang · rustApr 11, 2021

  • library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address

    CriticalCVSS 9.1No exploitEPSS 3%

    rust-lang · rustAug 7, 2021

  • Rust OS Command Injection/Argument Injection vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    rust-lang · rustSep 4, 2024

  • Regular expression denial of service in Rust's regex crate

    HighCVSS 7.5Proof of conceptEPSS 14%

    rust-lang · regexMar 8, 2022

  • The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sa

    HighCVSS 8.1No exploitEPSS 2%

    rust-lang · rustMay 13, 2019

  • In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed

    HighCVSS 8.2No exploitEPSS 2%

    rust-lang · rustApr 14, 2021

  • The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in r

    HighCVSS 7.8No exploitEPSS 2%

    rust-lang · rustJul 9, 2018

  • Extracting malicious crates can corrupt arbitrary files

    HighCVSS 8.1No exploitEPSS 1%

    rust-lang · cargoSep 14, 2022

  • In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.

    HighCVSS 7.5No exploitEPSS 2%

    rust-lang · rustApr 11, 2021

  • In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (un

    HighCVSS 7.5No exploitEPSS 2%

    rust-lang · rustApr 11, 2021

  • Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and

    HighCVSS 7.8No exploitEPSS 1%

    rust-lang · rustAug 20, 2018

  • An issue was discovered in the futures-task crate before 0.3.6 for Rust.

    HighCVSS 7.8No exploitEPSS 0%

    rust-lang · futures-taskDec 31, 2020

  • In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.

    HighCVSS 7.5No exploitEPSS 1%

    rust-lang · rustApr 11, 2021

  • In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once whe

    HighCVSS 7.5No exploitEPSS 1%

    rust-lang · rustApr 11, 2021

  • In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.

    HighCVSS 7.5No exploitEPSS 1%

    rust-lang · rustApr 11, 2021

  • Cargo prior to Rust 1.26.0 may download the wrong dependency

    HighCVSS 7.5No exploitEPSS 1%

    rust-lang · rustSep 30, 2019

  • request smuggling in async-h1

    HighCVSS 7.5No exploitEPSS 1%

    rust-lang · async-h1Dec 21, 2020

  • Cargo not respecting umask when extracting crate archives

    HighCVSS 7.3Proof of conceptEPSS 1%

    rust-lang · cargoAug 4, 2023

  • Extracting malicious crates can fill the file system

    MediumCVSS 6.5No exploitEPSS 1%

    rust-lang · cargoSep 14, 2022

  • CVE-2026-5223
    26Monitor

    Crates in third party registries can override the cached source of other crates

    MediumCVSS 6.5No exploitEPSS 0%

    rust-lang · cargoMay 25, 2026