|
198121
|
9.1 |
CRITICAL
Network
|
simple-slab_project
|
simple-slab
|
An issue was discovered in the simple-slab crate before 0.3.3 for Rust. index() allows an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35892
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198122
|
7.5 |
HIGH
Network
|
ordnung_project
|
ordnung
|
An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via a remove() double free.
|
CWE-415
Double Free
|
CVE-2020-35891
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198123
|
7.5 |
HIGH
Network
|
ordnung_project
|
ordnung
|
An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via out-of-bounds access for large capacity.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35890
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198124
|
8.1 |
HIGH
Network
|
crayon_project
|
crayon
|
An issue was discovered in the crayon crate through 2020-08-31 for Rust. A TOCTOU issue has a resultant memory safety violation via HandleLike.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-35889
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198125
|
9.8 |
CRITICAL
Network
|
arr_project
|
arr
|
An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-35888
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198126
|
9.8 |
CRITICAL
Network
|
arr_project
|
arr
|
An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-35887
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198127
|
4.7 |
MEDIUM
Local
|
arr_project
|
arr
|
An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race.
|
CWE-362
Race Condition
|
CVE-2020-35886
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198128
|
9.8 |
CRITICAL
Network
|
alpm-rs_project
|
alpm-rs
|
An issue was discovered in the alpm-rs crate through 2020-08-20 for Rust. StrcCtx performs improper memory deallocation.
|
CWE-415
Double Free
|
CVE-2020-35885
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198129
|
6.5 |
MEDIUM
Network
|
tiny-http_project fedoraproject
|
tiny-http fedora
|
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-35884
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198130
|
9.1 |
CRITICAL
Network
|
mozwire_project
|
mozwire
|
An issue was discovered in the mozwire crate through 2020-08-18 for Rust. A ../ directory-traversal situation allows overwriting local files that have .conf at the end of the filename.
|
CWE-22
Path Traversal
|
CVE-2020-35883
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|