|
198731
|
8.1 |
HIGH
Network
|
tiny_future_project
|
tiny_future
|
An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits.
|
CWE-362
Race Condition
|
CVE-2020-36438
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198732
|
8.1 |
HIGH
Network
|
conqueue_project
|
conqueue
|
An issue was discovered in the conqueue crate before 0.4.0 for Rust. There are unconditional implementations of Send and Sync for QueueSender<T>.
|
CWE-362
Race Condition
|
CVE-2020-36437
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198733
|
8.1 |
HIGH
Network
|
unicycle_project
|
unicycle
|
An issue was discovered in the unicycle crate before 0.7.1 for Rust. PinSlab<T> and Unordered<T, S> do not have bounds on their Send and Sync traits.
|
CWE-362
Race Condition
|
CVE-2020-36436
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198734
|
8.1 |
HIGH
Network
|
ruspiro-singleton_project
|
ruspiro-singleton
|
An issue was discovered in the ruspiro-singleton crate before 0.4.1 for Rust. In Singleton, Send and Sync do not have bounds checks.
|
CWE-362
Race Condition
|
CVE-2020-36435
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198735
|
9.8 |
CRITICAL
Network
|
sys-info_project
|
sys-info
|
An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free.
|
CWE-415
Double Free
|
CVE-2020-36434
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198736
|
7.5 |
HIGH
Network
|
aeplay
|
chunky
|
An issue was discovered in the chunky crate through 2020-08-25 for Rust. The Chunk API does not honor an alignment requirement.
|
NVD-CWE-noinfo
|
CVE-2020-36433
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198737
|
9.8 |
CRITICAL
Network
|
alg_ds_project
|
alg_ds
|
An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().
|
CWE-908
Use of Uninitialized Resource
|
CVE-2020-36432
|
2024-11-21 14:29 |
2021-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198738
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_data_center jira_service_desk jira_service_management
|
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from v…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-36239
|
2024-11-21 14:29 |
2021-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198739
|
5.5 |
MEDIUM
Local
|
unicorn-engine
|
unicorn_engine
|
Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36431
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198740
|
7.8 |
HIGH
Local
|
libass_project fedoraproject
|
libass fedora
|
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-36430
|
2024-11-21 14:29 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|