rust-lang kayıtları
rust-lang üreticisine ait 39 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %94,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-415 Double Free2
- CWE-190 Integer Overflow or Wraparound2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
39 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2024-24576Kavram kanıtı | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windowsfedoraproject · fedora · CWE-78 | Kritik10,0 | — | %20,3 | 9 Nis 2024 |
41Planlayın | CVE-2024-3566İstismar yok | Command injection vulnerability in programing languages on Microsoft Windows operating system.haskell · process library · CWE-77 | Kritik9,8 | — | %6,9 | 10 Nis 2024 |
40Planlayın | CVE-2018-1000810İstismar yok | The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integerust-lang · rust · CWE-190 | Kritik9,8 | — | %3,0 | 8 Eki 2018 |
40Planlayın | CVE-2021-31162İstismar yok | In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.rust-lang · rust · CWE-415 | Kritik9,8 | — | %2,9 | 14 Nis 2021 |
40Planlayın | CVE-2021-28879İstismar yok | In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.rust-lang · rust · CWE-190 | Kritik9,8 | — | %2,4 | 11 Nis 2021 |
40Planlayın | CVE-2020-36318İstismar yok | In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain crust-lang · rust · CWE-415 | Kritik9,8 | — | %1,7 | 11 Nis 2021 |
37İzleyin | CVE-2021-29922İstismar yok | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address rust-lang · rust | Kritik9,1 | — | %2,6 | 7 Ağu 2021 |
35İzleyin | CVE-2024-43402İstismar yok | Rust OS Command Injection/Argument Injection vulnerabilityrust-lang · rust · CWE-78 | Yüksek8,8 | — | %0,7 | 4 Eyl 2024 |
34İzleyin | CVE-2022-24713Kavram kanıtı | Regular expression denial of service in Rust's regex craterust-lang · regex · CWE-400 | Yüksek7,5 | — | %14,5 | 8 Mar 2022 |
33İzleyin | CVE-2019-12083İstismar yok | The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sarust-lang · rust · CWE-125 | Yüksek8,1 | — | %2,2 | 13 May 2019 |
33İzleyin | CVE-2020-36323İstismar yok | In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposedrust-lang · rust · CWE-134 | Yüksek8,2 | — | %2,0 | 14 Nis 2021 |
32İzleyin | CVE-2018-1000622İstismar yok | The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rrust-lang · rust · CWE-427 | Yüksek7,8 | — | %1,8 | 9 Tem 2018 |
32İzleyin | CVE-2022-36113İstismar yok | Extracting malicious crates can corrupt arbitrary filesrust-lang · cargo · CWE-22 | Yüksek8,1 | — | %1,2 | 14 Eyl 2022 |
31İzleyin | CVE-2021-28875İstismar yok | In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.rust-lang · rust · CWE-252 | Yüksek7,5 | — | %2,1 | 11 Nis 2021 |
31İzleyin | CVE-2021-28878İstismar yok | In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (unrust-lang · rust · CWE-119 | Yüksek7,5 | — | %2,0 | 11 Nis 2021 |
31İzleyin | CVE-2018-1000657İstismar yok | Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and rust-lang · rust · CWE-119 | Yüksek7,8 | — | %0,5 | 20 Ağu 2018 |
31İzleyin | CVE-2020-35906İstismar yok | An issue was discovered in the futures-task crate before 0.3.6 for Rust.rust-lang · futures-task · CWE-416 | Yüksek7,8 | — | %0,5 | 31 Ara 2020 |
30İzleyin | CVE-2020-36317İstismar yok | In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.rust-lang · rust · CWE-787 | Yüksek7,5 | — | %1,5 | 11 Nis 2021 |
30İzleyin | CVE-2021-28877İstismar yok | In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once wherust-lang · rust · CWE-119 | Yüksek7,5 | — | %1,4 | 11 Nis 2021 |
30İzleyin | CVE-2015-20001İstismar yok | In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.rust-lang · rust · CWE-119 | Yüksek7,5 | — | %1,3 | 11 Nis 2021 |
30İzleyin | CVE-2019-16760İstismar yok | Cargo prior to Rust 1.26.0 may download the wrong dependencyrust-lang · rust · CWE-16 | Yüksek7,5 | — | %1,3 | 30 Eyl 2019 |
30İzleyin | CVE-2020-26281İstismar yok | request smuggling in async-h1rust-lang · async-h1 · CWE-444 | Yüksek7,5 | — | %1,0 | 21 Ara 2020 |
29İzleyin | CVE-2023-38497Kavram kanıtı | Cargo not respecting umask when extracting crate archivesrust-lang · cargo · CWE-278 | Yüksek7,3 | — | %0,7 | 4 Ağu 2023 |
26İzleyin | CVE-2022-36114İstismar yok | Extracting malicious crates can fill the file systemrust-lang · cargo · CWE-400 | Orta6,5 | — | %0,9 | 14 Eyl 2022 |
26İzleyin | CVE-2026-5223İstismar yok | Crates in third party registries can override the cached source of other cratesrust-lang · cargo · CWE-61 | Orta6,5 | — | %0,4 | 25 May 2026 |
- CVE-2024-2457646Planlayın
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
KritikCVSS 10,0Kavram kanıtıEPSS %20fedoraproject · fedora9 Nis 2024
- CVE-2024-356641Planlayın
Command injection vulnerability in programing languages on Microsoft Windows operating system.
KritikCVSS 9,8İstismar yokEPSS %7haskell · process library10 Nis 2024
- CVE-2018-100081040Planlayın
The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Intege
KritikCVSS 9,8İstismar yokEPSS %3rust-lang · rust8 Eki 2018
- CVE-2021-3116240Planlayın
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
KritikCVSS 9,8İstismar yokEPSS %3rust-lang · rust14 Nis 2021
- CVE-2021-2887940Planlayın
In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow.
KritikCVSS 9,8İstismar yokEPSS %2rust-lang · rust11 Nis 2021
- CVE-2020-3631840Planlayın
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain c
KritikCVSS 9,8İstismar yokEPSS %2rust-lang · rust11 Nis 2021
- CVE-2021-2992237İzleyin
library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address
KritikCVSS 9,1İstismar yokEPSS %3rust-lang · rust7 Ağu 2021
- CVE-2024-4340235İzleyin
Rust OS Command Injection/Argument Injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1rust-lang · rust4 Eyl 2024
- CVE-2022-2471334İzleyin
Regular expression denial of service in Rust's regex crate
YüksekCVSS 7,5Kavram kanıtıEPSS %14rust-lang · regex8 Mar 2022
- CVE-2019-1208333İzleyin
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's sa
YüksekCVSS 8,1İstismar yokEPSS %2rust-lang · rust13 May 2019
- CVE-2020-3632333İzleyin
In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed
YüksekCVSS 8,2İstismar yokEPSS %2rust-lang · rust14 Nis 2021
- CVE-2018-100062232İzleyin
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in r
YüksekCVSS 7,8İstismar yokEPSS %2rust-lang · rust9 Tem 2018
- CVE-2022-3611332İzleyin
Extracting malicious crates can corrupt arbitrary files
YüksekCVSS 8,1İstismar yokEPSS %1rust-lang · cargo14 Eyl 2022
- CVE-2021-2887531İzleyin
In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context.
YüksekCVSS 7,5İstismar yokEPSS %2rust-lang · rust11 Nis 2021
- CVE-2021-2887831İzleyin
In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (un
YüksekCVSS 7,5İstismar yokEPSS %2rust-lang · rust11 Nis 2021
- CVE-2018-100065731İzleyin
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and
YüksekCVSS 7,8İstismar yokEPSS %1rust-lang · rust20 Ağu 2018
- CVE-2020-3590631İzleyin
An issue was discovered in the futures-task crate before 0.3.6 for Rust.
YüksekCVSS 7,8İstismar yokEPSS %0rust-lang · futures-task31 Ara 2020
- CVE-2020-3631730İzleyin
In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem.
YüksekCVSS 7,5İstismar yokEPSS %1rust-lang · rust11 Nis 2021
- CVE-2021-2887730İzleyin
In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once whe
YüksekCVSS 7,5İstismar yokEPSS %1rust-lang · rust11 Nis 2021
- CVE-2015-2000130İzleyin
In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe.
YüksekCVSS 7,5İstismar yokEPSS %1rust-lang · rust11 Nis 2021
- CVE-2019-1676030İzleyin
Cargo prior to Rust 1.26.0 may download the wrong dependency
YüksekCVSS 7,5İstismar yokEPSS %1rust-lang · rust30 Eyl 2019
- CVE-2020-2628130İzleyin
request smuggling in async-h1
YüksekCVSS 7,5İstismar yokEPSS %1rust-lang · async-h121 Ara 2020
- CVE-2023-3849729İzleyin
Cargo not respecting umask when extracting crate archives
YüksekCVSS 7,3Kavram kanıtıEPSS %1rust-lang · cargo4 Ağu 2023
- CVE-2022-3611426İzleyin
Extracting malicious crates can fill the file system
OrtaCVSS 6,5İstismar yokEPSS %1rust-lang · cargo14 Eyl 2022
- CVE-2026-522326İzleyin
Crates in third party registries can override the cached source of other crates
OrtaCVSS 6,5İstismar yokEPSS %0rust-lang · cargo25 May 2026