crates.io incidents

Recent crates.io vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNcrates.io

clear_on_drop is unmaintained

clear_on_drop is unmaintained

2 days ago
MEDIUMcrates.io

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

5 days ago
HIGHcrates.io

mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS

mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS

5 days ago
HIGHcrates.io

gix-sec safe.directory protections absent for elevated administrators

gix-sec safe.directory protections absent for elevated administrators

6 days ago
UNKNOWNcrates.io

Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics

Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics

6 days ago
UNKNOWNcrates.io

`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code

`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code

1 week ago
UNKNOWNcrates.io

`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code

`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code

1 week ago
CRITICALcrates.io

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)

1 week ago
HIGHcrates.io

CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

1 week ago
HIGHcrates.io

CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval

CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval

1 week ago
MODERATEcrates.io

SurrealDB allows bypass of deny-net flags via DNS resolution

SurrealDB allows bypass of deny-net flags via DNS resolution

1 week ago
MEDIUMcrates.io

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

1 week ago
CRITICALcrates.io

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

1 week ago
HIGHcrates.io

CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

1 week ago
HIGHcrates.io

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

1 week ago
HIGHcrates.io

CodeWhale: js_execution leaks parent environment to model context via missing env scrub

CodeWhale: js_execution leaks parent environment to model context via missing env scrub

1 week ago
HIGHcrates.io

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

1 week ago
HIGHcrates.io

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

1 week ago
CRITICALcrates.io

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

1 week ago
MODERATEcrates.io

Hurl: Cookies in Cookies section leak when redirecting to a different host

Hurl: Cookies in Cookies section leak when redirecting to a different host

1 week ago
UNKNOWNcrates.io

`zbus_polkit`: authorization bypass via PID reuse

`zbus_polkit`: authorization bypass via PID reuse

2 weeks ago
MODERATEcrates.io

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation

2 weeks ago
MODERATEcrates.io

Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref

Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref

2 weeks ago
HIGHcrates.io

gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

2 weeks ago
HIGHcrates.io

datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS

datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS

2 weeks ago
MEDIUMcrates.io

Wasmtime has a leak in WASIp1 `fd_renumber` implementation

Wasmtime has a leak in WASIp1 `fd_renumber` implementation

2 weeks ago
UNKNOWNcrates.io

Path traversal in apimock-server's file-serving fallback

Path traversal in apimock-server's file-serving fallback

2 weeks ago
UNKNOWNcrates.io

Path traversal in apimock's file-serving fallback

Path traversal in apimock's file-serving fallback

2 weeks ago
UNKNOWNcrates.io

Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)

Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)

3 weeks ago
MODERATEcrates.io

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

3 weeks ago
MODERATEcrates.io

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

3 weeks ago
HIGHcrates.io

postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

3 weeks ago
MODERATEcrates.io

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

3 weeks ago
UNKNOWNcrates.io

Malicious code in arone (crates.io)

Malicious code in arone (crates.io)

3 weeks ago
UNKNOWNcrates.io

Malicious code in proc_macro_en (crates.io)

Malicious code in proc_macro_en (crates.io)

3 weeks ago
UNKNOWNcrates.io

`proc-macro1` was removed from crates.io due to malicious code

`proc-macro1` was removed from crates.io due to malicious code

3 weeks ago
UNKNOWNcrates.io

`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency

`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency

3 weeks ago
UNKNOWNcrates.io

`arone` was removed from crates.io due to malicious code

`arone` was removed from crates.io due to malicious code

3 weeks ago
UNKNOWNcrates.io

`aronenao` was removed from crates.io due to malicious code

`aronenao` was removed from crates.io due to malicious code

3 weeks ago
UNKNOWNcrates.io

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

3 weeks ago
UNKNOWNcrates.io

Malicious code in arrayref (crates.io)

Malicious code in arrayref (crates.io)

3 weeks ago
UNKNOWNcrates.io

Malicious code in append_only_vec (crates.io)

Malicious code in append_only_vec (crates.io)

3 weeks ago
UNKNOWNcrates.io

Malicious code in proc_macro1 (crates.io)

Malicious code in proc_macro1 (crates.io)

3 weeks ago
UNKNOWNcrates.io

Malicious code in aronenao (crates.io)

Malicious code in aronenao (crates.io)

3 weeks ago
UNKNOWNcrates.io

Malicious code in tinymember (crates.io)

Malicious code in tinymember (crates.io)

3 weeks ago
UNKNOWNcrates.io

Malicious code in internment (crates.io)

Malicious code in internment (crates.io)

3 weeks ago
UNKNOWNcrates.io

`tinymember` was removed from crates.io due to affiliation with malicious code

`tinymember` was removed from crates.io due to affiliation with malicious code

3 weeks ago
UNKNOWNcrates.io

Malicious code in aovine (crates.io)

Malicious code in aovine (crates.io)

3 weeks ago
UNKNOWNcrates.io

`internment` 0.8.7 was removed from crates.io due to a malicious dependency

`internment` 0.8.7 was removed from crates.io due to a malicious dependency

3 weeks ago
UNKNOWNcrates.io

`proc-macro-en` was removed from crates.io due to malicious code

`proc-macro-en` was removed from crates.io due to malicious code

3 weeks ago
MODERATEcrates.io

block_buffer: panic corrupts inline buffer position

block_buffer: panic corrupts inline buffer position

3 weeks ago
MODERATEcrates.io

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

4 weeks ago
UNKNOWNcrates.io

h2 unbounded empty DATA frames

h2 unbounded empty DATA frames

4 weeks ago
HIGHcrates.io

Legacy `azure_core` writes the `authorization` header value to logs

Legacy `azure_core` writes the `authorization` header value to logs

4 weeks ago
HIGHcrates.io

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

4 weeks ago
MEDIUMcrates.io

s2n-quic has excessive memory allocation

s2n-quic has excessive memory allocation

4 weeks ago
HIGHcrates.io

nimiq-blockchain: Validity store off by one error

nimiq-blockchain: Validity store off by one error

4 weeks ago
UNKNOWNcrates.io

Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)

Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)

1 month ago
UNKNOWNcrates.io

Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)

Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)

1 month ago
UNKNOWNcrates.io

Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)

Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)

1 month ago
UNKNOWNcrates.io

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

1 month ago
UNKNOWNcrates.io

Safe ErrorRegistry APIs can cause undefined behavior

Safe ErrorRegistry APIs can cause undefined behavior

1 month ago
UNKNOWNcrates.io

Streaming AEAD does not authenticate stream structure

Streaming AEAD does not authenticate stream structure

1 month ago
UNKNOWNcrates.io

Low-level GCM ignores the operation nonce

Low-level GCM ignores the operation nonce

1 month ago
UNKNOWNcrates.io

Ed25519 identity public keys permit universal signature forgery

Ed25519 identity public keys permit universal signature forgery

1 month ago
UNKNOWNcrates.io

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

1 month ago
HIGHcrates.io

A `BigInt` division panics, and two neighbouring operations answer wrongly in silence

A `BigInt` division panics, and two neighbouring operations answer wrongly in silence

1 month ago
UNKNOWNcrates.io

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

1 month ago
UNKNOWNcrates.io

`sevenz-rust` is unmaintained

`sevenz-rust` is unmaintained

1 month ago
UNKNOWNcrates.io

Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics

Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics

1 month ago
UNKNOWNcrates.io

`nostr-relay-pool` is unmaintained

`nostr-relay-pool` is unmaintained

1 month ago
UNKNOWNcrates.io

`nostr-keyring` is unmaintained

`nostr-keyring` is unmaintained

1 month ago
UNKNOWNcrates.io

`nostr-relay-builder` is unmaintained

`nostr-relay-builder` is unmaintained

1 month ago
HIGHcrates.io

Russh: Channel-scoped server callbacks can be reached without an open channel

Russh: Channel-scoped server callbacks can be reached without an open channel

1 month agoEPSS 0%
HIGHcrates.io

NIP-44 v2 decryption permits resource exhaustion

NIP-44 v2 decryption permits resource exhaustion

1 month ago
HIGHcrates.io

Empty NIP-50 search filters can panic

Empty NIP-50 search filters can panic

1 month ago
HIGHcrates.io

Verification cache poisoning allows forged Nostr events to bypass signature validation

Verification cache poisoning allows forged Nostr events to bypass signature validation

1 month ago
HIGHcrates.io

Processing of unverified relay events

Processing of unverified relay events

1 month ago
HIGHcrates.io

NIP-98 authorization parsing permits resource exhaustion

NIP-98 authorization parsing permits resource exhaustion

1 month ago
HIGHcrates.io

Wallet event parsers accept unauthenticated events

Wallet event parsers accept unauthenticated events

1 month ago
MEDIUMcrates.io

NIP-04 parsing amplifies malformed ciphertext memory use

NIP-04 parsing amplifies malformed ciphertext memory use

1 month ago
HIGHcrates.io

Debug output exposes NIP-46 and NIP-60 credentials

Debug output exposes NIP-46 and NIP-60 credentials

1 month ago
HIGHcrates.io

Relay authentication challenges can exhaust memory

Relay authentication challenges can exhaust memory

1 month ago
MEDIUMcrates.io

Stores can mix up type indices between engines

Stores can mix up type indices between engines

1 month ago
MODERATEcrates.io

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

1 month ago
UNKNOWNcrates.io

Preemption and traps during bulk operations enable breaking internal VM state

Preemption and traps during bulk operations enable breaking internal VM state

1 month ago
UNKNOWNcrates.io

Unix `BROWSER` handling allows browser argument injection

Unix `BROWSER` handling allows browser argument injection

1 month ago
HIGHcrates.io

Remote Denial of Service via malformed NIP-04 IV

Remote Denial of Service via malformed NIP-04 IV

1 month ago
HIGHcrates.io

Remote Denial of Service via malformed NIP‑44 v2 payload

Remote Denial of Service via malformed NIP‑44 v2 payload

1 month ago
MEDIUMcrates.io

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

1 month ago
MEDIUMcrates.io

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

1 month ago
HIGHcrates.io

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

1 month ago
MEDIUMcrates.io

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

1 month ago
MODERATEcrates.io

serde_with: KeyValueMap serialization panics on empty sequence or map entries

serde_with: KeyValueMap serialization panics on empty sequence or map entries

2 months ago
UNKNOWNcrates.io

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

2 months ago
UNKNOWNcrates.io

Uint shift operations: incorrect overflow flags and truncated shift amounts

Uint shift operations: incorrect overflow flags and truncated shift amounts

2 months ago
MODERATEcrates.io

async-tar PAX extension-header desync enables tar entry/content smuggling

async-tar PAX extension-header desync enables tar entry/content smuggling

2 months ago
MODERATEcrates.io

Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set

Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set

2 months ago
MEDIUMcrates.io

SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages

SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages

2 months ago
HIGHcrates.io

SurrealDB: Graph traversal bypasses table SELECT permissions

SurrealDB: Graph traversal bypasses table SELECT permissions

2 months ago
MEDIUMcrates.io

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

2 months ago
MEDIUMcrates.io

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

2 months ago
MEDIUMcrates.io

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

2 months ago
HIGHcrates.io

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

2 months ago
MEDIUMcrates.io

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

2 months ago
HIGHcrates.io

SurrealDB has Denial of Service in JSON parser due to nested objects

SurrealDB has Denial of Service in JSON parser due to nested objects

2 months ago
MEDIUMcrates.io

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

2 months ago
HIGHcrates.io

tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

2 months ago
MEDIUMcrates.io

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

2 months ago
HIGHcrates.io

tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load

tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load

2 months ago
HIGHcrates.io

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

3 months agoEPSS 0%
UNKNOWNcrates.io

Leak in WASIp1 `fd_renumber` implementation

Leak in WASIp1 `fd_renumber` implementation

3 months ago
HIGHcrates.io

PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators

PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators

3 months ago
MODERATEcrates.io

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

3 months ago
UNKNOWNcrates.io

Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

3 months ago
UNKNOWNcrates.io

Panic decoding a malformed `hstore` value allows denial of service

Panic decoding a malformed `hstore` value allows denial of service

3 months ago
UNKNOWNcrates.io

Panic on a `DataRow` with fewer fields than columns allows denial of service

Panic on a `DataRow` with fewer fields than columns allows denial of service

3 months ago
UNKNOWNcrates.io

DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

3 months ago
HIGHcrates.io

wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

3 months ago
HIGHcrates.io

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

3 months ago
MEDIUMcrates.io

russh server userauth state is not reset when authentication principal changes

russh server userauth state is not reset when authentication principal changes

3 months ago
HIGHcrates.io

russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets

russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets

3 months ago
MODERATEcrates.io

tar has a PAX header desynchronization issue

tar has a PAX header desynchronization issue

3 months ago
UNKNOWNcrates.io

Use-after-free

Use-after-free

3 months ago
HIGHcrates.io

Russh: Unchecked CryptoVec allocation and growth handling is reachable

Russh: Unchecked CryptoVec allocation and growth handling is reachable

3 months ago
MODERATEcrates.io

rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers

rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers

3 months ago
MODERATEcrates.io

rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution

rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution

4 months ago
UNKNOWNcrates.io

TLS hostname verification disabled when using Boring TLS backend

TLS hostname verification disabled when using Boring TLS backend

4 months agoEPSS 0%
UNKNOWNcrates.io

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

4 months ago
UNKNOWNcrates.io

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

4 months ago
UNKNOWNcrates.io

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

4 months ago
UNKNOWNcrates.io

Crafted archives can cause a use-after-free during deserialization

Crafted archives can cause a use-after-free during deserialization

4 months ago
MODERATEcrates.io

hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression

hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression

4 months ago
MODERATEcrates.io

wasmtime has a panic when allocating a table exceeding the size of the host's address space

wasmtime has a panic when allocating a table exceeding the size of the host's address space

4 months ago
MODERATEcrates.io

imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling

imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling

4 months ago
CRITICALcrates.io

gix-fs: Symlink prefix-reuse allows worktree escape during checkout

gix-fs: Symlink prefix-reuse allows worktree escape during checkout

4 months ago
HIGHcrates.io

hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses

hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses

4 months ago
MODERATEcrates.io

rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding

rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding

4 months ago
MODERATEcrates.io

imageproc: integer overflow in kernel size check leads to out-of-bounds read

imageproc: integer overflow in kernel size check leads to out-of-bounds read

4 months ago
MODERATEcrates.io

astral-tokio-tar is Vulnerable to PAX Header Desynchronization

astral-tokio-tar is Vulnerable to PAX Header Desynchronization

4 months ago
HIGHcrates.io

ldap3_proto has LDAP Filter stack exhaustion

ldap3_proto has LDAP Filter stack exhaustion

4 months ago
LOWcrates.io

astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks

astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks

4 months ago
CRITICALcrates.io

rmcp Streamable HTTP server transport has a DNS rebinding vulnerability

rmcp Streamable HTTP server transport has a DNS rebinding vulnerability

4 months ago
HIGHcrates.io

rpassword affected by partial password reveal when input is interrupted

rpassword affected by partial password reveal when input is interrupted

4 months ago
LOWcrates.io

webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed

webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed

4 months ago
HIGHcrates.io

awslabs/tough Delegated Roles have a Signature Threshold Bypass

awslabs/tough Delegated Roles have a Signature Threshold Bypass

4 months ago
HIGHcrates.io

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

4 months ago
HIGHcrates.io

gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data

gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data

4 months ago
HIGHcrates.io

awslabs/tough is Missing Delegated Metadata Validation

awslabs/tough is Missing Delegated Metadata Validation

4 months ago
HIGHcrates.io

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

4 months ago
MEDIUMcrates.io

Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability

Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability

4 months agoEPSS 1%
HIGHcrates.io

gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository

gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository

4 months ago
HIGHcrates.io

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

4 months ago
CRITICALcrates.io

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

4 months ago
HIGHcrates.io

gix-transport: HTTP credentials leaked to redirected host in curl backend

gix-transport: HTTP credentials leaked to redirected host in curl backend

4 months ago
UNKNOWNcrates.io

bitmaps is unmaintained

bitmaps is unmaintained

4 months ago
UNKNOWNcrates.io

smartstring is unmaintained

smartstring is unmaintained

4 months ago
UNKNOWNcrates.io

im-rc is unmaintained

im-rc is unmaintained

4 months ago
UNKNOWNcrates.io

sized-chunks is unmaintained

sized-chunks is unmaintained

4 months ago
UNKNOWNcrates.io

im is unmaintained

im is unmaintained

4 months ago
HIGHcrates.io

rustls-webpki: Denial of service via panic on malformed CRL BIT STRING

rustls-webpki: Denial of service via panic on malformed CRL BIT STRING

4 months ago
HIGHcrates.io

Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior

Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior

4 months ago
HIGHcrates.io

russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler

russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler

4 months ago
HIGHcrates.io

rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer

rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer

4 months ago
HIGHcrates.io

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

4 months ago
MODERATEcrates.io

actix-http has HTTP/1.1 CL.TE Request Smuggling

actix-http has HTTP/1.1 CL.TE Request Smuggling

4 months ago
MEDIUMcrates.io

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

4 months ago
HIGHcrates.io

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

4 months ago
CRITICALcrates.io

uutils coreutils has an Untrusted Search Path

uutils coreutils has an Untrusted Search Path

4 months ago
HIGHcrates.io

rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1

rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1

4 months ago
HIGHcrates.io

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails

4 months ago
HIGHcrates.io

uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths

uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths

4 months ago
HIGHcrates.io

uutils coreutils has a Link Following issue

uutils coreutils has a Link Following issue

4 months ago
HIGHcrates.io

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

4 months ago
LOWcrates.io

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

4 months ago
MEDIUMcrates.io

uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries

uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries

4 months ago
CRITICALcrates.io

uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition

uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition

4 months ago
HIGHcrates.io

rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check

rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check

4 months ago
MEDIUMcrates.io

uutils coreutils has an Improper Input Validation Issue in its env Utility

uutils coreutils has an Improper Input Validation Issue in its env Utility

4 months ago
HIGHcrates.io

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition

4 months ago
HIGHcrates.io

rust-openssl has incorrect bounds assertion in aes key wrap

rust-openssl has incorrect bounds assertion in aes key wrap

4 months ago
HIGHcrates.io

uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition

uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition

4 months ago
MEDIUMcrates.io

uutils coreutils has an Incorrect Permission Assignment for Critical Resource

uutils coreutils has an Incorrect Permission Assignment for Critical Resource

4 months ago
MEDIUMcrates.io

uutils coreutils has an Unchecked Return Value Issue

uutils coreutils has an Unchecked Return Value Issue

4 months ago
HIGHcrates.io

uutils coreutils has a Link Following Issue

uutils coreutils has a Link Following Issue

4 months ago
MEDIUMcrates.io

webpki: Name constraints for URI names were incorrectly accepted

webpki: Name constraints for URI names were incorrectly accepted

5 months ago
MEDIUMcrates.io

webpki: Name constraints were accepted for certificates asserting a wildcard name

webpki: Name constraints were accepted for certificates asserting a wildcard name

5 months ago
HIGHcrates.io

thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics

thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics

5 months ago
LOWcrates.io

Rand is unsound with a custom logger using rand::rng()

Rand is unsound with a custom logger using rand::rng()

5 months ago
CRITICALcrates.io

Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

5 months ago
MODERATEcrates.io

Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend

Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend

5 months ago
MODERATEcrates.io

Wasmtime has out-of-bounds write or crash when transcoding component model strings

Wasmtime has out-of-bounds write or crash when transcoding component model strings

5 months ago
LOWcrates.io

Wasmtime has use-after-free bug after cloning `wasmtime::Linker`

Wasmtime has use-after-free bug after cloning `wasmtime::Linker`

5 months ago
HIGHcrates.io

Wasmtime: Panic when transcoding misaligned utf-16 strings

Wasmtime: Panic when transcoding misaligned utf-16 strings

5 months ago
HIGHcrates.io

Wasmtime has host panic when Winch compiler executes `table.fill`

Wasmtime has host panic when Winch compiler executes `table.fill`

5 months ago
LOWcrates.io

Wasmtime has data leakage between pooling allocator instances

Wasmtime has data leakage between pooling allocator instances

5 months ago
HIGHcrates.io

Wasmtime has host data leakage with 64-bit tables and Winch

Wasmtime has host data leakage with 64-bit tables and Winch

5 months ago
HIGHcrates.io

Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64

Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64

5 months ago
CRITICALcrates.io

Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

5 months ago
HIGHcrates.io

Wasmtime has a possible panic when lifting `flags` component value

Wasmtime has a possible panic when lifting `flags` component value

5 months ago
HIGHcrates.io

Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

5 months ago
UNKNOWNcrates.io

Stubbed cryptography without warnings

Stubbed cryptography without warnings

5 months ago
HIGHcrates.io

libcrux-sha3: Incorrect output from SHAKE squeeze functions

libcrux-sha3: Incorrect output from SHAKE squeeze functions

5 months ago
HIGHcrates.io

tar-rs incorrectly ignores PAX size headers if header size is nonzero

tar-rs incorrectly ignores PAX size headers if header size is nonzero

5 months ago
HIGHcrates.io

webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic

webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic

5 months ago
HIGHcrates.io

CRL Distribution Point Scope Check Logic Error in AWS-LC

CRL Distribution Point Scope Check Logic Error in AWS-LC

5 months ago
HIGHcrates.io

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

5 months ago
HIGHcrates.io

tar-rs `unpack_in` can chmod arbitrary directories by following symlinks

tar-rs `unpack_in` can chmod arbitrary directories by following symlinks

5 months ago
MEDIUMcrates.io

astral-tokio-tar insufficiently validates PAX extensions during extraction

astral-tokio-tar insufficiently validates PAX extensions during extraction

6 months ago
HIGHcrates.io

lz4_flex's decompression can leak information from uninitialized memory or reused output buffer

lz4_flex's decompression can leak information from uninitialized memory or reused output buffer

6 months ago
HIGHcrates.io

Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing

Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing

6 months ago
MEDIUMcrates.io

actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects

actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects

6 months ago
HIGHcrates.io

AWS-LC has PKCS7_verify Signature Validation Bypass

AWS-LC has PKCS7_verify Signature Validation Bypass

6 months ago
HIGHcrates.io

AWS-LC has Timing Side-Channel in AES-CCM Tag Verification

AWS-LC has Timing Side-Channel in AES-CCM Tag Verification

6 months ago
HIGHcrates.io

AWS-LC has PKCS7_verify Certificate Chain Validation Bypass

AWS-LC has PKCS7_verify Certificate Chain Validation Bypass

6 months ago
MODERATEcrates.io

Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

6 months ago
MODERATEcrates.io

Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

6 months ago
MODERATEcrates.io

Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

6 months ago
LOWcrates.io

Unsoundness in opt-in ARMv8 assembly backend for `keccak`

Unsoundness in opt-in ARMv8 assembly backend for `keccak`

6 months ago
LOWcrates.io

Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`

Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`

7 months ago
UNKNOWNcrates.io

Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext

Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext

7 months ago
MODERATEcrates.io

[actix-files] Panic triggered by empty Range header in GET request for static file

[actix-files] Panic triggered by empty Range header in GET request for static file

7 months ago
MODERATEcrates.io

actix-files has a possible exposure of information vulnerability

actix-files has a possible exposure of information vulnerability

7 months ago
UNKNOWNcrates.io

Unnecessary clamping of seed reduces seed entropy to 251 bits

Unnecessary clamping of seed reduces seed entropy to 251 bits

7 months ago
MODERATEcrates.io

time vulnerable to stack exhaustion Denial of Service attack

time vulnerable to stack exhaustion Denial of Service attack

7 months ago
LOWcrates.io

git2 has potential undefined behavior when dereferencing Buf struct

git2 has potential undefined behavior when dereferencing Buf struct

7 months ago
MODERATEcrates.io

jsonwebtoken has Type Confusion that leads to potential authorization bypass

jsonwebtoken has Type Confusion that leads to potential authorization bypass

7 months ago
MODERATEcrates.io

bytes has integer overflow in BytesMut::reserve

bytes has integer overflow in BytesMut::reserve

7 months ago
MODERATEcrates.io

Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64

Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64

7 months ago
HIGHcrates.io

oneshot has potential Use After Free when used asynchronously

oneshot has potential Use After Free when used asynchronously

7 months ago
UNKNOWNcrates.io

Incorrect X25519 clamping check rejects all secrets on import

Incorrect X25519 clamping check rejects all secrets on import

7 months ago
UNKNOWNcrates.io

X25519 secret validation did not check buffer length or clamping

X25519 secret validation did not check buffer length or clamping

7 months ago
HIGHcrates.io

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

8 months ago
MEDIUMcrates.io

AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value

AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value

8 months ago
LOWcrates.io

`IterMut` violates Stacked Borrows by invalidating internal pointer

`IterMut` violates Stacked Borrows by invalidating internal pointer

8 months ago
LOWcrates.io

rsa crate has potential panic on a prime being equal to 1

rsa crate has potential panic on a prime being equal to 1

8 months ago
MODERATEcrates.io

gix-date can create non-utf8 string with `TimeBuf::as_str`

gix-date can create non-utf8 string with `TimeBuf::as_str`

8 months ago
UNKNOWNcrates.io

`Bitmap::try_from(&[u8])` can create invalid values

`Bitmap::try_from(&[u8])` can create invalid values

8 months ago
HIGHcrates.io

Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short

Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short

9 months ago
CRITICALcrates.io

Critical Use-After-Free in Wasmi's Linear Memory

Critical Use-After-Free in Wasmi's Linear Memory

9 months ago
MEDIUMcrates.io

Wasmtime provides unsound API access to a WebAssembly shared linear memory

Wasmtime provides unsound API access to a WebAssembly shared linear memory

10 months ago
HIGHcrates.io

astral-tokio-tar Vulnerable to PAX Header Desynchronization

astral-tokio-tar Vulnerable to PAX Header Desynchronization

10 months ago
CRITICALcrates.io

risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`

risc0-aggregation: before 0.9

11 months ago
LOWcrates.io

Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal

Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal

11 months ago
LOWcrates.io

Tracing logging user input may result in poisoning logs with ANSI escape sequences

Tracing logging user input may result in poisoning logs with ANSI escape sequences

1 year ago
MODERATEcrates.io

webp crate may expose memory contents when encoding an image

webp crate may expose memory contents when encoding an image

1 year ago
MODERATEcrates.io

slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check

slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check

1 year ago
HIGHcrates.io

quiche connection ID retirement can trigger an infinite loop

quiche connection ID retirement can trigger an infinite loop

1 year ago
HIGHcrates.io

russh is missing overflow checks during channel windows adjust

russh is missing overflow checks during channel windows adjust

1 year ago
MEDIUMcrates.io

Wasmtime CLI is vulnerable to host panic through its fd_renumber function

Wasmtime CLI is vulnerable to host panic through its fd_renumber function

1 year ago
HIGHcrates.io

users may append `root` to group listings

users may append `root` to group listings

1 year ago
MEDIUMcrates.io

Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables

Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables

1 year ago
MEDIUMcrates.io

Deno run with --allow-read and --deny-read flags results in allowed

Deno run with --allow-read and --deny-read flags results in allowed

1 year ago
HIGHcrates.io

Deno's AES GCM authentication tags are not verified

Deno's AES GCM authentication tags are not verified

1 year ago
MEDIUMcrates.io

sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders

sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders

1 year ago
MEDIUMcrates.io

sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others

sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others

1 year ago
UNKNOWNcrates.io

`FormatContext` stream accessors can cause undefined behavior from safe code

`FormatContext` stream accessors can cause undefined behavior from safe code

1 year ago
UNKNOWNcrates.io

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

1 year ago
MODERATEcrates.io

SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)

SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)

1 year ago
CRITICALcrates.io

SurrealDB server-takeover via SurrealQL injection on backup import

SurrealDB server-takeover via SurrealQL injection on backup import

1 year ago
MODERATEcrates.io

crossbeam-channel Vulnerable to Double Free on Drop

crossbeam-channel Vulnerable to Double Free on Drop

1 year ago
LOWcrates.io

Tokio broadcast channel calls clone in parallel, but does not require `Sync`

Tokio broadcast channel calls clone in parallel, but does not require `Sync`

1 year ago
HIGHcrates.io

gitoxide does not detect SHA-1 collision attacks

gitoxide does not detect SHA-1 collision attacks

1 year ago
MODERATEcrates.io

rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`

rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`

1 year ago
CRITICALcrates.io

Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`

Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`

1 year ago
LOWcrates.io

PyO3 Risk of buffer overflow in `PyString::from_object`

PyO3 Risk of buffer overflow in `PyString::from_object`

1 year ago
MODERATEcrates.io

xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.

xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.

xmas-elf: before 0.10

1 year ago
HIGHcrates.io

zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write

zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write

1 year ago
UNKNOWNcrates.io

Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write

Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write

1 year ago
MODERATEcrates.io

Crash due to uncontrolled recursion in protobuf crate

Crash due to uncontrolled recursion in protobuf crate

1 year ago
MODERATEcrates.io

Some AES functions may panic when overflow checking is enabled in ring

Some AES functions may panic when overflow checking is enabled in ring

1 year ago
LOWcrates.io

Fyrox has unsound usages of `Vec::from_raw_parts`

Fyrox has unsound usages of `Vec::from_raw_parts`

fyrox-core: 0.28.1 → 0.36

1 year ago
MODERATEcrates.io

Hickory DNS failure to verify self-signed RRSIG for DNSKEYs

Hickory DNS failure to verify self-signed RRSIG for DNSKEYs

1 year ago
MODERATEcrates.io

Hickory DNS's DNSSEC validation may accept broken authentication chains

Hickory DNS's DNSSEC validation may accept broken authentication chains

1 year ago
MODERATEcrates.io

rust-openssl ssl::select_next_proto use after free

rust-openssl ssl::select_next_proto use after free

1 year ago
MODERATEcrates.io

fast-fault has a segmentation fault due to lack of bound check

fast-fault has a segmentation fault due to lack of bound check

1 year ago
HIGHcrates.io

gix-worktree-state nonexclusive checkout sets executable files world-writable

gix-worktree-state nonexclusive checkout sets executable files world-writable

1 year ago
MODERATEcrates.io

rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

1 year ago
LOWcrates.io

SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type

SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type

1 year ago
MODERATEcrates.io

`idna` accepts Punycode labels that do not produce any non-ASCII when decoded

`idna` accepts Punycode labels that do not produce any non-ASCII when decoded

1 year ago
LOWcrates.io

Unsound usages of `std::slice::from_raw_parts`

Unsound usages of `std::slice::from_raw_parts`

1 year ago
HIGHcrates.io

Borsh serialization of HashMap is non-canonical

Borsh serialization of HashMap is non-canonical

1 year ago
MODERATEcrates.io

Unsoundness in anstream

Unsoundness in anstream

1 year ago
MODERATEcrates.io

`ruzstd` uninit and out-of-bounds memory reads

`ruzstd` uninit and out-of-bounds memory reads

1 year ago
MODERATEcrates.io

rustls network-reachable panic in `Acceptor::accept`

rustls network-reachable panic in `Acceptor::accept`

1 year ago
HIGHcrates.io

SurrealDB has an Uncaught Exception Handling Nonexistent Role

SurrealDB has an Uncaught Exception Handling Nonexistent Role

1 year ago
LOWcrates.io

s2n-tls has undefined behavior at process exit

s2n-tls has undefined behavior at process exit

1 year ago
MODERATEcrates.io

Mimalloc Can Allocate Memory with Bad Alignment

Mimalloc Can Allocate Memory with Bad Alignment

1 year ago
LOWcrates.io

`fast-float` has multiple soundness issues

`fast-float` has multiple soundness issues

1 year ago
LOWcrates.io

Wasmtime doesn't fully sandbox all the Windows device filenames

Wasmtime doesn't fully sandbox all the Windows device filenames

1 year ago
LOWcrates.io

cap-std doesn't fully sandbox all the Windows device filenames

cap-std doesn't fully sandbox all the Windows device filenames

1 year ago
MEDIUMcrates.io

Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations

Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations

1 year ago
HIGHcrates.io

wasmtime has a runtime crash when combining tail calls with trapping imports

wasmtime has a runtime crash when combining tail calls with trapping imports

1 year ago
HIGHcrates.io

SurrealDB: Improper Authorization in Select Permissions

SurrealDB: Improper Authorization in Select Permissions

1 year ago
MEDIUMcrates.io

Tonic has remotely exploitable denial of service vulnerability

Tonic has remotely exploitable denial of service vulnerability

1 year ago
LOWcrates.io

lexical-core has multiple soundness issues

lexical-core has multiple soundness issues

1 year ago
HIGHcrates.io

gix-path improperly resolves configuration path reported by Git

gix-path improperly resolves configuration path reported by Git

2 years ago
HIGHcrates.io

Denial of service in quinn-proto when using `Endpoint::retry()`

Denial of service in quinn-proto when using `Endpoint::retry()`

2 years ago
MEDIUMcrates.io

gix-path uses local config across repos when it is the highest scope

gix-path uses local config across repos when it is the highest scope

2 years ago
MODERATEcrates.io

SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts

SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts

2 years ago
HIGHcrates.io

Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects

Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects

boa_engine: 0.16 → 0.19.0

2 years ago
MEDIUMcrates.io

s2n-tls's mTLS API ordering may skip client authentication

s2n-tls's mTLS API ordering may skip client authentication

2 years ago
LOWcrates.io

The kstring integration in gix-attributes is unsound

The kstring integration in gix-attributes is unsound

2 years ago
MEDIUMcrates.io

Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files

Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files

2 years ago
MEDIUMcrates.io

openssl's `MemBio::get_buf` has undefined behavior with empty buffers

openssl's `MemBio::get_buf` has undefined behavior with empty buffers

2 years ago
HIGHcrates.io

gix-path can use a fake program files location

gix-path can use a fake program files location

2 years ago
MEDIUMcrates.io

matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check

matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check

2 years ago
MEDIUMcrates.io

vodozemac's usage of non-constant time base64 decoder could lead to leakage of secret key material

vodozemac's usage of non-constant time base64 decoder could lead to leakage of secret key material

2 years ago
HIGHcrates.io

panic on parsing crafted phonenumber inputs

panic on parsing crafted phonenumber inputs

2 years ago
HIGHcrates.io

zerovec incorrectly uses `#[repr(packed)]`

zerovec incorrectly uses `#[repr(packed)]`

2 years ago
HIGHcrates.io

zerovec-derive incorrectly uses `#[repr(packed)]`

zerovec-derive incorrectly uses `#[repr(packed)]`

2 years ago
HIGHcrates.io

Unlimited number of NTS-KE connections can crash ntpd-rs server

Unlimited number of NTS-KE connections can crash ntpd-rs server

2 years ago
MEDIUMcrates.io

curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`

curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`

2 years ago
MEDIUMcrates.io

Symlink bypasses filesystem sandbox

Symlink bypasses filesystem sandbox

2 years ago
LOWcrates.io

s2n-tls has a potentially observable differences in RSA premaster secret handling

s2n-tls has a potentially observable differences in RSA premaster secret handling

2 years ago
HIGHcrates.io

Unable to generate the correct character set

Unable to generate the correct character set

2 years ago
MEDIUMcrates.io

gix refs and paths with reserved Windows device names access the devices

gix refs and paths with reserved Windows device names access the devices

2 years ago
CRITICALcrates.io

gix traversal outside working tree enables arbitrary code execution

gix traversal outside working tree enables arbitrary code execution

2 years ago
HIGHcrates.io

matrix-sdk-crypto contains a log exposure of private key of the server-side key backup

matrix-sdk-crypto contains a log exposure of private key of the server-side key backup

2 years ago
HIGHcrates.io

Spin applications with specific configuration vulnerable to potential network sandbox escape

Spin applications with specific configuration vulnerable to potential network sandbox escape

2 years ago
CRITICALcrates.io

Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag

Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag

2 years ago
MEDIUMcrates.io

vodozemac has degraded secret zeroization capabilities

vodozemac has degraded secret zeroization capabilities

2 years ago
CRITICALcrates.io

Apollo Router vulnerable to Critical Regression In Query Plan Cache

Apollo Router vulnerable to Critical Regression In Query Plan Cache

2 years ago
HIGHcrates.io

Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

2 years ago
HIGHcrates.io

Denial of Service Vulnerability in Rustls Library

Denial of Service Vulnerability in Rustls Library

2 years ago
HIGHcrates.io

gix-transport indirect code execution via malicious username

gix-transport indirect code execution via malicious username

gix: before 0.62

2 years ago
MEDIUMcrates.io

h2 servers vulnerable to degradation of service with CONTINUATION Flood

h2 servers vulnerable to degradation of service with CONTINUATION Flood

2 years ago
HIGHcrates.io

cassandra-rs's non-idiomatic use of iterators leads to use after free

cassandra-rs's non-idiomatic use of iterators leads to use after free

2 years ago
HIGHcrates.io

eyre: Parts of Report are dropped as the wrong type during downcast

eyre: Parts of Report are dropped as the wrong type during downcast

2 years ago
MEDIUMcrates.io

Wasmtime vulnerable to panic when using a dropped extenref-typed element segment

Wasmtime vulnerable to panic when using a dropped extenref-typed element segment

2 years ago
HIGHcrates.io

tls-listener affected by the slow loris vulnerability with default configuration

tls-listener affected by the slow loris vulnerability with default configuration

2 years ago
MEDIUMcrates.io

Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters

Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters

2 years ago
MEDIUMcrates.io

Deno's improper suffix match testing for DENO_AUTH_TOKENS

Deno's improper suffix match testing for DENO_AUTH_TOKENS

2 years ago
CRITICALcrates.io

Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass

Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass

2 years ago
CRITICALcrates.io

Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI stripping

Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI stripping

2 years ago
MEDIUMcrates.io

Insufficient permission checking in `Deno.makeTemp*` APIs

Insufficient permission checking in `Deno.makeTemp*` APIs

2 years ago
MEDIUMcrates.io

Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination

Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination

2 years ago
HIGHcrates.io

Mio's tokens for named pipes may be delivered after deregistration

Mio's tokens for named pipes may be delivered after deregistration

2 years ago
HIGHcrates.io

libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2

libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2

2 years ago
HIGHcrates.io

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in trillium-http and trillium-client

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in trillium-http and trillium-client

2 years ago
HIGHcrates.io

Any authenticated user may obtain private message details from other users on the same instance

Any authenticated user may obtain private message details from other users on the same instance

2 years ago
MODERATEcrates.io

Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)

Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)

2 years ago
HIGHcrates.io

Uncaught Exception processing HTTP Headers in SurrealDB

Uncaught Exception processing HTTP Headers in SurrealDB

2 years ago
HIGHcrates.io

CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential

CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential

2 years ago
HIGHcrates.io

Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders

Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders

2 years ago
HIGHcrates.io

Rust EVM erroneousle handles `record_external_operation` error return

Rust EVM erroneousle handles `record_external_operation` error return

2 years ago
MEDIUMcrates.io

`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access

`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access

2 years ago
MODERATEcrates.io

unsafe-libyaml unaligned write of u64 on 32-bit and 16-bit platforms

unsafe-libyaml unaligned write of u64 on 32-bit and 16-bit platforms

2 years ago
HIGHcrates.io

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

paramiko: 2.5.0 → 3.4.0

2 years ago
CRITICALcrates.io

SurrealDB: Full Table Permissions by Default

SurrealDB: Full Table Permissions by Default

2 years ago
CRITICALcrates.io

Wasmer filesystem sandbox not enforced

Wasmer filesystem sandbox not enforced

2 years ago
MODERATEcrates.io

`openssl` `X509StoreRef::objects` is unsound

`openssl` `X509StoreRef::objects` is unsound

2 years ago
HIGHcrates.io

Marvin Attack: potential key recovery through timing sidechannels

Marvin Attack: potential key recovery through timing sidechannels

2 years ago
HIGHcrates.io

Marvin Attack: potential key recovery through timing sidechannels

Marvin Attack: potential key recovery through timing sidechannels

2 years ago
MEDIUMcrates.io

stellar-strkey vulnerable to panic in SignedPayload::from_payload

stellar-strkey vulnerable to panic in SignedPayload::from_payload

2 years ago
HIGHcrates.io

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

2 years ago
HIGHcrates.io

Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions

Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions

2 years ago
HIGHcrates.io

rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion

rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion

2 years ago
HIGHcrates.io

Tungstenite allows remote attackers to cause a denial of service

Tungstenite allows remote attackers to cause a denial of service

2 years ago
HIGHcrates.io

SQLpage vulnerable to public exposure of database credentials

SQLpage vulnerable to public exposure of database credentials

2 years ago
HIGHcrates.io

Denial of Service issue in quinn-proto

Denial of Service issue in quinn-proto

2 years ago
CRITICALcrates.io

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

SkiaSharp: 2.0.0 → 2.88.6

3 years ago
MODERATEcrates.io

Users vulnerable to unaligned read of `*const *const c_char` pointer

Users vulnerable to unaligned read of `*const *const c_char` pointer

3 years ago
HIGHcrates.io

Apollo Router Unnamed "Subscription" operation results in Denial-of-Service

Apollo Router Unnamed "Subscription" operation results in Denial-of-Service

3 years ago
MEDIUMcrates.io

Default functions in VolatileMemory trait lack bounds checks, potentially leading to out-of-bounds memory accesses

Default functions in VolatileMemory trait lack bounds checks, potentially leading to out-of-bounds memory accesses

3 years ago
HIGHcrates.io

webpki: CPU denial of service in certificate path building

webpki: CPU denial of service in certificate path building

3 years ago
LOWcrates.io

Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports

Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports

cargo: 1.60.0 → 1.72

3 years ago
HIGHcrates.io

rustls-webpki: CPU denial of service in certificate path building

rustls-webpki: CPU denial of service in certificate path building

3 years ago
HIGHcrates.io

zola Path Traversal vulnerability

zola Path Traversal vulnerability

3 years ago
HIGHcrates.io

twitch-tui's connection is not encrypted

twitch-tui's connection is not encrypted

3 years ago
LOWcrates.io

atty potential unaligned read

atty potential unaligned read

3 years ago
MEDIUMcrates.io

`openssl` `X509VerifyParamRef::set_host` buffer over-read

`openssl` `X509VerifyParamRef::set_host` buffer over-read

3 years ago
MEDIUMcrates.io

Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles

Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles

3 years ago
MEDIUMcrates.io

ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`

ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`

3 years ago
HIGHcrates.io

Missing "--allow-net" permission check for built-in Node modules

Missing "--allow-net" permission check for built-in Node modules

3 years ago
HIGHcrates.io

Improper handling of NTS cookie length that could crash the ntpd-rs server

Improper handling of NTS cookie length that could crash the ntpd-rs server

3 years ago
MEDIUMcrates.io

Tauri Open Redirect Vulnerability Possibly Exposes IPC to External Sites

Tauri Open Redirect Vulnerability Possibly Exposes IPC to External Sites

3 years ago
MODERATEcrates.io

spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisers

spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisers

3 years ago
MEDIUMcrates.io

Comrak AST node data is not validated (GHSL-2023-049)

Comrak AST node data is not validated (GHSL-2023-049)

3 years ago
CRITICALcrates.io

Interactive `run` permission prompt spoofing via improper ANSI neutralization

Interactive `run` permission prompt spoofing via improper ANSI neutralization

3 years ago
MODERATEcrates.io

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

3 years ago
MEDIUMcrates.io

wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64

wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64

3 years ago
CRITICALcrates.io

wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64

wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64

3 years ago
LOWcrates.io

Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all

Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all

3 years ago
HIGHcrates.io

openssl-src subject to Timing Oracle in RSA Decryption

openssl-src subject to Timing Oracle in RSA Decryption

3 years ago
HIGHcrates.io

openssl-src contains Read Buffer Overflow in X.509 Name Constraint

openssl-src contains Read Buffer Overflow in X.509 Name Constraint

3 years ago
HIGHcrates.io

openssl-src subject to NULL dereference validating DSA public key

openssl-src subject to NULL dereference validating DSA public key

3 years ago
HIGHcrates.io

openssl-src contains Double free after calling `PEM_read_bio_ex`

openssl-src contains Double free after calling `PEM_read_bio_ex`

3 years ago
HIGHcrates.io

openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`

openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`

3 years ago
HIGHcrates.io

openssl-src contains `NULL` dereference during PKCS7 data verification

openssl-src contains `NULL` dereference during PKCS7 data verification

3 years ago
HIGHcrates.io

openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions

openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions

3 years ago
LOWcrates.io

`tokio::io::ReadHalf<T>::unsplit` is Unsound

`tokio::io::ReadHalf<T>::unsplit` is Unsound

3 years ago
UNKNOWNcrates.io

Aliasing violation in `OrdSet` insertion

Aliasing violation in `OrdSet` insertion

3 years ago
MODERATEcrates.io

bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`

bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`

3 years ago
CRITICALcrates.io

Deno is vulnerable to race condition via interactive permission prompt spoofing

Deno is vulnerable to race condition via interactive permission prompt spoofing

3 years ago
MEDIUMcrates.io

Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe

Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe

3 years ago
HIGHcrates.io

Denial of service by double-checked locking in openssl-src

Denial of service by double-checked locking in openssl-src

3 years ago
CRITICALcrates.io

X.509 Email Address 4-byte Buffer Overflow

X.509 Email Address 4-byte Buffer Overflow

3 years ago
HIGHcrates.io

X.509 Email Address Variable Length Buffer Overflow

X.509 Email Address Variable Length Buffer Overflow

3 years ago
HIGHcrates.io

Using a Custom Cipher with `NID_undef` may lead to NULL encryption

Using a Custom Cipher with `NID_undef` may lead to NULL encryption

3 years ago
CRITICALcrates.io

typemap is Unmaintained

typemap is Unmaintained

4 years ago
CRITICALcrates.io

traitobject is Unmaintained

traitobject is Unmaintained

4 years ago
HIGHcrates.io

AES OCB fails to encrypt some bytes

AES OCB fails to encrypt some bytes

4 years ago
HIGHcrates.io

Out-of-bounds write in nix::unistd::getgrouplist

Out-of-bounds write in nix::unistd::getgrouplist

4 years ago
HIGHcrates.io

Parser creates invalid uninitialized value

Parser creates invalid uninitialized value

4 years ago
HIGHcrates.io

Cargo prior to Rust 1.26.0 may download the wrong dependency

Cargo prior to Rust 1.26.0 may download the wrong dependency

4 years ago
MEDIUMcrates.io

Integer overflow in the bundled Brotli C library

Integer overflow in the bundled Brotli C library

Microsoft.NETCore.App.Runtime.linux-arm: 3.0.0 → 3.1.23

4 years ago
HIGHcrates.io

Incorrect MAC key used in the RC4-MD5 ciphersuite

Incorrect MAC key used in the RC4-MD5 ciphersuite

4 years ago
HIGHcrates.io

Resource leakage when decoding certificates and keys

Resource leakage when decoding certificates and keys

4 years ago
MEDIUMcrates.io

`OCSP_basic_verify` may incorrectly verify the response signing certificate

`OCSP_basic_verify` may incorrectly verify the response signing certificate

4 years ago
HIGHcrates.io

openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates

openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates

4 years ago
CRITICALcrates.io

Out-of-bounds Write in nix

Out-of-bounds Write in nix

4 years ago
HIGHcrates.io

Async-h1 request smuggling possible with long unread bodies

Async-h1 request smuggling possible with long unread bodies

4 years ago
CRITICALcrates.io

coreos-installer improperly verifies GPG signature when decompressing gzipped artifact

coreos-installer improperly verifies GPG signature when decompressing gzipped artifact

4 years ago
CRITICALcrates.io

Free of uninitialized memory in telemetry

Free of uninitialized memory in telemetry

5 years ago
HIGHcrates.io

Segmentation fault in time

Segmentation fault in time

5 years ago
CRITICALcrates.io

Double free in http

Double free in http

5 years ago
HIGHcrates.io

Integer Overflow/Infinite Loop in the http crate

Integer Overflow/Infinite Loop in the http crate

5 years ago
CRITICALcrates.io

Incorrect cast in anymap

Incorrect cast in anymap

5 years ago
HIGHcrates.io

XSS in mdBook

XSS in mdBook

5 years ago
CRITICALcrates.io

Out of bounds write in traitobject

Out of bounds write in traitobject

5 years ago
HIGHcrates.io

Null pointer deference in openssl-src

Null pointer deference in openssl-src

5 years ago
HIGHcrates.io

Integer Overflow in Chunked Transfer-Encoding

Integer Overflow in Chunked Transfer-Encoding

5 years ago
MEDIUMcrates.io

Lenient Parsing of Content-Length Header When Prefixed with Plus Sign

Lenient Parsing of Content-Length Header When Prefixed with Plus Sign

5 years ago
UNKNOWNcrates.io

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

5 years ago

Tooling for crates.io

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenNuGetPackagistPubPyPIRubyGemsSwiftURLnpm