rust-lang records
39 published records for vendor rust-lang.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 94.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-415 Double Free2
- CWE-190 Integer Overflow or Wraparound2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2024-24576Proof of concept | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windowsfedoraproject · fedora · CWE-78 | Critical10.0 | — | 20.3% | Apr 9, 2024 |
41Plan | CVE-2024-3566No exploit | Command injection vulnerability in programing languages on Microsoft Windows operating system.haskell · process library · CWE-77 | Critical9.8 | — | 6.9% | Apr 10, 2024 |
40Plan | CVE-2018-1000810No exploit | The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integerust-lang · rust · CWE-190 | Critical9.8 | — | 3.0% | Oct 8, 2018 |
40Plan | CVE-2021-31162No exploit | In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.rust-lang · rust · CWE-415 | Critical9.8 | — | 2.9% | Apr 14, 2021 |
40Plan | CVE-2021-28879No exploit | In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.rust-lang · rust · CWE-190 | Critical9.8 | — | 2.4% | Apr 11, 2021 |
40Plan | CVE-2020-36318No exploit | In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain crust-lang · rust · CWE-415 | Critical9.8 | — | 1.7% | Apr 11, 2021 |
37Monitor | CVE-2021-29922No exploit | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address rust-lang · rust | Critical9.1 | — | 2.6% | Aug 7, 2021 |
35Monitor | CVE-2024-43402No exploit | Rust OS Command Injection/Argument Injection vulnerabilityrust-lang · rust · CWE-78 | High8.8 | — | 0.7% | Sep 4, 2024 |
34Monitor | CVE-2022-24713Proof of concept | Regular expression denial of service in Rust's regex craterust-lang · regex · CWE-400 | High7.5 | — | 14.5% | Mar 8, 2022 |
33Monitor | CVE-2019-12083No exploit | The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sarust-lang · rust · CWE-125 | High8.1 | — | 2.2% | May 13, 2019 |
33Monitor | CVE-2020-36323No exploit | In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposedrust-lang · rust · CWE-134 | High8.2 | — | 2.0% | Apr 14, 2021 |
32Monitor | CVE-2018-1000622No exploit | The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rrust-lang · rust · CWE-427 | High7.8 | — | 1.8% | Jul 9, 2018 |
32Monitor | CVE-2022-36113No exploit | Extracting malicious crates can corrupt arbitrary filesrust-lang · cargo · CWE-22 | High8.1 | — | 1.2% | Sep 14, 2022 |
31Monitor | CVE-2021-28875No exploit | In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.rust-lang · rust · CWE-252 | High7.5 | — | 2.1% | Apr 11, 2021 |
31Monitor | CVE-2021-28878No exploit | In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (unrust-lang · rust · CWE-119 | High7.5 | — | 2.0% | Apr 11, 2021 |
31Monitor | CVE-2018-1000657No exploit | Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and rust-lang · rust · CWE-119 | High7.8 | — | 0.5% | Aug 20, 2018 |
31Monitor | CVE-2020-35906No exploit | An issue was discovered in the futures-task crate before 0.3.6 for Rust.rust-lang · futures-task · CWE-416 | High7.8 | — | 0.5% | Dec 31, 2020 |
30Monitor | CVE-2020-36317No exploit | In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.rust-lang · rust · CWE-787 | High7.5 | — | 1.5% | Apr 11, 2021 |
30Monitor | CVE-2021-28877No exploit | In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once wherust-lang · rust · CWE-119 | High7.5 | — | 1.4% | Apr 11, 2021 |
30Monitor | CVE-2015-20001No exploit | In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.rust-lang · rust · CWE-119 | High7.5 | — | 1.3% | Apr 11, 2021 |
30Monitor | CVE-2019-16760No exploit | Cargo prior to Rust 1.26.0 may download the wrong dependencyrust-lang · rust · CWE-16 | High7.5 | — | 1.3% | Sep 30, 2019 |
30Monitor | CVE-2020-26281No exploit | request smuggling in async-h1rust-lang · async-h1 · CWE-444 | High7.5 | — | 1.0% | Dec 21, 2020 |
29Monitor | CVE-2023-38497Proof of concept | Cargo not respecting umask when extracting crate archivesrust-lang · cargo · CWE-278 | High7.3 | — | 0.7% | Aug 4, 2023 |
26Monitor | CVE-2022-36114No exploit | Extracting malicious crates can fill the file systemrust-lang · cargo · CWE-400 | Medium6.5 | — | 0.9% | Sep 14, 2022 |
26Monitor | CVE-2026-5223No exploit | Crates in third party registries can override the cached source of other cratesrust-lang · cargo · CWE-61 | Medium6.5 | — | 0.4% | May 25, 2026 |
- CVE-2024-2457646Plan
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
CriticalCVSS 10.0Proof of conceptEPSS 20%fedoraproject · fedoraApr 9, 2024
- CVE-2024-356641Plan
Command injection vulnerability in programing languages on Microsoft Windows operating system.
CriticalCVSS 9.8No exploitEPSS 7%haskell · process libraryApr 10, 2024
- CVE-2018-100081040Plan
The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Intege
CriticalCVSS 9.8No exploitEPSS 3%rust-lang · rustOct 8, 2018
- CVE-2021-3116240Plan
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
CriticalCVSS 9.8No exploitEPSS 3%rust-lang · rustApr 14, 2021
- CVE-2021-2887940Plan
In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.
CriticalCVSS 9.8No exploitEPSS 2%rust-lang · rustApr 11, 2021
- CVE-2020-3631840Plan
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain c
CriticalCVSS 9.8No exploitEPSS 2%rust-lang · rustApr 11, 2021
- CVE-2021-2992237Monitor
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address
CriticalCVSS 9.1No exploitEPSS 3%rust-lang · rustAug 7, 2021
- CVE-2024-4340235Monitor
Rust OS Command Injection/Argument Injection vulnerability
HighCVSS 8.8No exploitEPSS 1%rust-lang · rustSep 4, 2024
- CVE-2022-2471334Monitor
Regular expression denial of service in Rust's regex crate
HighCVSS 7.5Proof of conceptEPSS 14%rust-lang · regexMar 8, 2022
- CVE-2019-1208333Monitor
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sa
HighCVSS 8.1No exploitEPSS 2%rust-lang · rustMay 13, 2019
- CVE-2020-3632333Monitor
In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed
HighCVSS 8.2No exploitEPSS 2%rust-lang · rustApr 14, 2021
- CVE-2018-100062232Monitor
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in r
HighCVSS 7.8No exploitEPSS 2%rust-lang · rustJul 9, 2018
- CVE-2022-3611332Monitor
Extracting malicious crates can corrupt arbitrary files
HighCVSS 8.1No exploitEPSS 1%rust-lang · cargoSep 14, 2022
- CVE-2021-2887531Monitor
In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.
HighCVSS 7.5No exploitEPSS 2%rust-lang · rustApr 11, 2021
- CVE-2021-2887831Monitor
In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (un
HighCVSS 7.5No exploitEPSS 2%rust-lang · rustApr 11, 2021
- CVE-2018-100065731Monitor
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and
HighCVSS 7.8No exploitEPSS 1%rust-lang · rustAug 20, 2018
- CVE-2020-3590631Monitor
An issue was discovered in the futures-task crate before 0.3.6 for Rust.
HighCVSS 7.8No exploitEPSS 0%rust-lang · futures-taskDec 31, 2020
- CVE-2020-3631730Monitor
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.
HighCVSS 7.5No exploitEPSS 1%rust-lang · rustApr 11, 2021
- CVE-2021-2887730Monitor
In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once whe
HighCVSS 7.5No exploitEPSS 1%rust-lang · rustApr 11, 2021
- CVE-2015-2000130Monitor
In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.
HighCVSS 7.5No exploitEPSS 1%rust-lang · rustApr 11, 2021
- CVE-2019-1676030Monitor
Cargo prior to Rust 1.26.0 may download the wrong dependency
HighCVSS 7.5No exploitEPSS 1%rust-lang · rustSep 30, 2019
- CVE-2020-2628130Monitor
request smuggling in async-h1
HighCVSS 7.5No exploitEPSS 1%rust-lang · async-h1Dec 21, 2020
- CVE-2023-3849729Monitor
Cargo not respecting umask when extracting crate archives
HighCVSS 7.3Proof of conceptEPSS 1%rust-lang · cargoAug 4, 2023
- CVE-2022-3611426Monitor
Extracting malicious crates can fill the file system
MediumCVSS 6.5No exploitEPSS 1%rust-lang · cargoSep 14, 2022
- CVE-2026-522326Monitor
Crates in third party registries can override the cached source of other crates
MediumCVSS 6.5No exploitEPSS 0%rust-lang · cargoMay 25, 2026