Записи rust-lang
39 опубликованных записей вендора rust-lang.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 94,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-415 Double Free2
- CWE-190 Integer Overflow or Wraparound2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
39 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2024-24576Proof of concept | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windowsfedoraproject · fedora · CWE-78 | Критическая10,0 | — | 20,3 % | 9 апр. 2024 г. |
41В плане | CVE-2024-3566Эксплойта нет | Command injection vulnerability in programing languages on Microsoft Windows operating system.haskell · process library · CWE-77 | Критическая9,8 | — | 6,9 % | 10 апр. 2024 г. |
40В плане | CVE-2018-1000810Эксплойта нет | The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integerust-lang · rust · CWE-190 | Критическая9,8 | — | 3,0 % | 8 окт. 2018 г. |
40В плане | CVE-2021-31162Эксплойта нет | In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.rust-lang · rust · CWE-415 | Критическая9,8 | — | 2,9 % | 14 апр. 2021 г. |
40В плане | CVE-2021-28879Эксплойта нет | In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.rust-lang · rust · CWE-190 | Критическая9,8 | — | 2,4 % | 11 апр. 2021 г. |
40В плане | CVE-2020-36318Эксплойта нет | In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain crust-lang · rust · CWE-415 | Критическая9,8 | — | 1,7 % | 11 апр. 2021 г. |
37Наблюдать | CVE-2021-29922Эксплойта нет | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address rust-lang · rust | Критическая9,1 | — | 2,6 % | 7 авг. 2021 г. |
35Наблюдать | CVE-2024-43402Эксплойта нет | Rust OS Command Injection/Argument Injection vulnerabilityrust-lang · rust · CWE-78 | Высокая8,8 | — | 0,7 % | 4 сент. 2024 г. |
34Наблюдать | CVE-2022-24713Proof of concept | Regular expression denial of service in Rust's regex craterust-lang · regex · CWE-400 | Высокая7,5 | — | 14,5 % | 8 мар. 2022 г. |
33Наблюдать | CVE-2019-12083Эксплойта нет | The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sarust-lang · rust · CWE-125 | Высокая8,1 | — | 2,2 % | 13 мая 2019 г. |
33Наблюдать | CVE-2020-36323Эксплойта нет | In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposedrust-lang · rust · CWE-134 | Высокая8,2 | — | 2,0 % | 14 апр. 2021 г. |
32Наблюдать | CVE-2018-1000622Эксплойта нет | The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rrust-lang · rust · CWE-427 | Высокая7,8 | — | 1,8 % | 9 июл. 2018 г. |
32Наблюдать | CVE-2022-36113Эксплойта нет | Extracting malicious crates can corrupt arbitrary filesrust-lang · cargo · CWE-22 | Высокая8,1 | — | 1,2 % | 14 сент. 2022 г. |
31Наблюдать | CVE-2021-28875Эксплойта нет | In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.rust-lang · rust · CWE-252 | Высокая7,5 | — | 2,1 % | 11 апр. 2021 г. |
31Наблюдать | CVE-2021-28878Эксплойта нет | In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (unrust-lang · rust · CWE-119 | Высокая7,5 | — | 2,0 % | 11 апр. 2021 г. |
31Наблюдать | CVE-2018-1000657Эксплойта нет | Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and rust-lang · rust · CWE-119 | Высокая7,8 | — | 0,5 % | 20 авг. 2018 г. |
31Наблюдать | CVE-2020-35906Эксплойта нет | An issue was discovered in the futures-task crate before 0.3.6 for Rust.rust-lang · futures-task · CWE-416 | Высокая7,8 | — | 0,5 % | 31 дек. 2020 г. |
30Наблюдать | CVE-2020-36317Эксплойта нет | In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.rust-lang · rust · CWE-787 | Высокая7,5 | — | 1,5 % | 11 апр. 2021 г. |
30Наблюдать | CVE-2021-28877Эксплойта нет | In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once wherust-lang · rust · CWE-119 | Высокая7,5 | — | 1,4 % | 11 апр. 2021 г. |
30Наблюдать | CVE-2015-20001Эксплойта нет | In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.rust-lang · rust · CWE-119 | Высокая7,5 | — | 1,3 % | 11 апр. 2021 г. |
30Наблюдать | CVE-2019-16760Эксплойта нет | Cargo prior to Rust 1.26.0 may download the wrong dependencyrust-lang · rust · CWE-16 | Высокая7,5 | — | 1,3 % | 30 сент. 2019 г. |
30Наблюдать | CVE-2020-26281Эксплойта нет | request smuggling in async-h1rust-lang · async-h1 · CWE-444 | Высокая7,5 | — | 1,0 % | 21 дек. 2020 г. |
29Наблюдать | CVE-2023-38497Proof of concept | Cargo not respecting umask when extracting crate archivesrust-lang · cargo · CWE-278 | Высокая7,3 | — | 0,7 % | 4 авг. 2023 г. |
26Наблюдать | CVE-2022-36114Эксплойта нет | Extracting malicious crates can fill the file systemrust-lang · cargo · CWE-400 | Средняя6,5 | — | 0,9 % | 14 сент. 2022 г. |
26Наблюдать | CVE-2026-5223Эксплойта нет | Crates in third party registries can override the cached source of other cratesrust-lang · cargo · CWE-61 | Средняя6,5 | — | 0,4 % | 25 мая 2026 г. |
- CVE-2024-2457646В плане
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
КритическаяCVSS 10,0Proof of conceptEPSS 20 %fedoraproject · fedora9 апр. 2024 г.
- CVE-2024-356641В плане
Command injection vulnerability in programing languages on Microsoft Windows operating system.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %haskell · process library10 апр. 2024 г.
- CVE-2018-100081040В плане
The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Intege
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %rust-lang · rust8 окт. 2018 г.
- CVE-2021-3116240В плане
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %rust-lang · rust14 апр. 2021 г.
- CVE-2021-2887940В плане
In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rust-lang · rust11 апр. 2021 г.
- CVE-2020-3631840В плане
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rust-lang · rust11 апр. 2021 г.
- CVE-2021-2992237Наблюдать
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %rust-lang · rust7 авг. 2021 г.
- CVE-2024-4340235Наблюдать
Rust OS Command Injection/Argument Injection vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %rust-lang · rust4 сент. 2024 г.
- CVE-2022-2471334Наблюдать
Regular expression denial of service in Rust's regex crate
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %rust-lang · regex8 мар. 2022 г.
- CVE-2019-1208333Наблюдать
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sa
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %rust-lang · rust13 мая 2019 г.
- CVE-2020-3632333Наблюдать
In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed
ВысокаяCVSS 8,2Эксплойта нетEPSS 2 %rust-lang · rust14 апр. 2021 г.
- CVE-2018-100062232Наблюдать
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in r
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %rust-lang · rust9 июл. 2018 г.
- CVE-2022-3611332Наблюдать
Extracting malicious crates can corrupt arbitrary files
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %rust-lang · cargo14 сент. 2022 г.
- CVE-2021-2887531Наблюдать
In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %rust-lang · rust11 апр. 2021 г.
- CVE-2021-2887831Наблюдать
In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (un
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %rust-lang · rust11 апр. 2021 г.
- CVE-2018-100065731Наблюдать
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %rust-lang · rust20 авг. 2018 г.
- CVE-2020-3590631Наблюдать
An issue was discovered in the futures-task crate before 0.3.6 for Rust.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %rust-lang · futures-task31 дек. 2020 г.
- CVE-2020-3631730Наблюдать
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rust-lang · rust11 апр. 2021 г.
- CVE-2021-2887730Наблюдать
In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once whe
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rust-lang · rust11 апр. 2021 г.
- CVE-2015-2000130Наблюдать
In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rust-lang · rust11 апр. 2021 г.
- CVE-2019-1676030Наблюдать
Cargo prior to Rust 1.26.0 may download the wrong dependency
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rust-lang · rust30 сент. 2019 г.
- CVE-2020-2628130Наблюдать
request smuggling in async-h1
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rust-lang · async-h121 дек. 2020 г.
- CVE-2023-3849729Наблюдать
Cargo not respecting umask when extracting crate archives
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %rust-lang · cargo4 авг. 2023 г.
- CVE-2022-3611426Наблюдать
Extracting malicious crates can fill the file system
СредняяCVSS 6,5Эксплойта нетEPSS 1 %rust-lang · cargo14 сент. 2022 г.
- CVE-2026-522326Наблюдать
Crates in third party registries can override the cached source of other crates
СредняяCVSS 6,5Эксплойта нетEPSS 0 %rust-lang · cargo25 мая 2026 г.