|
198311
|
9.8 |
CRITICAL
Network
|
rusqlite_project
|
rusqlite
|
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.
|
CWE-416
Use After Free
|
CVE-2020-35870
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198312
|
9.8 |
CRITICAL
Network
|
rusqlite_project
|
rusqlite
|
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2020-35869
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198313
|
9.8 |
CRITICAL
Network
|
rusqlite_project
|
rusqlite
|
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotification.
|
NVD-CWE-noinfo
|
CVE-2020-35868
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198314
|
9.8 |
CRITICAL
Network
|
rusqlite_project
|
rusqlite
|
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module.
|
NVD-CWE-noinfo
|
CVE-2020-35867
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198315
|
9.8 |
CRITICAL
Network
|
rusqlite_project
|
rusqlite
|
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor.
|
NVD-CWE-noinfo
|
CVE-2020-35866
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198316
|
7.5 |
HIGH
Network
|
os_str_bytes_project
|
os_str_bytes
|
An issue was discovered in the os_str_bytes crate before 2.0.0 for Rust. It has false expectations about char::from_u32_unchecked behavior.
|
NVD-CWE-noinfo
|
CVE-2020-35865
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198317
|
7.5 |
HIGH
Network
|
google
|
flatbuffers
|
An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can transmute values without unsafe blocks.
|
NVD-CWE-noinfo
|
CVE-2020-35864
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198318
|
9.8 |
CRITICAL
Network
|
hyper
|
hyper
|
An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interfa…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-35863
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198319
|
9.8 |
CRITICAL
Network
|
bitvec_project
|
bitvec
|
An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free.
|
CWE-415 CWE-416
Double Free Use After Free
|
CVE-2020-35862
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198320
|
7.5 |
HIGH
Network
|
bumpalo_project
|
bumpalo
|
An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35861
|
2024-11-21 14:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|