CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2021-38197

    Last Modified: 21 Nov 2024

    unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive.

    Published: 8 Aug 2021
    7.3
    High

    CVE-2021-23419

    Last Modified: 21 Nov 2024

    This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2020-36432

    Last Modified: 21 Nov 2024

    An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().

    Published: 8 Aug 2021
    7.5
    High

    CVE-2020-36433

    Last Modified: 21 Nov 2024

    An issue was discovered in the chunky crate through 2020-08-25 for Rust. The Chunk API does not honor an alignment requirement.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2020-36434

    Last Modified: 21 Nov 2024

    An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36435

    Last Modified: 21 Nov 2024

    An issue was discovered in the ruspiro-singleton crate before 0.4.1 for Rust. In Singleton, Send and Sync do not have bounds checks.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36436

    Last Modified: 21 Nov 2024

    An issue was discovered in the unicycle crate before 0.7.1 for Rust. PinSlab<T> and Unordered<T, S> do not have bounds on their Send and Sync traits.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36437

    Last Modified: 21 Nov 2024

    An issue was discovered in the conqueue crate before 0.4.0 for Rust. There are unconditional implementations of Send and Sync for QueueSender<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36438

    Last Modified: 21 Nov 2024

    An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36439

    Last Modified: 21 Nov 2024

    An issue was discovered in the ticketed_lock crate before 0.3.0 for Rust. There are unconditional implementations of Send for ReadTicket<T> and WriteTicket<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36440

    Last Modified: 21 Nov 2024

    An issue was discovered in the libsbc crate before 0.1.5 for Rust. For Decoder<R>, it implements Send for any R: Read.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36441

    Last Modified: 21 Nov 2024

    An issue was discovered in the abox crate before 0.4.1 for Rust. It implements Send and Sync for AtomicBox<T> with no requirement for T: Send and T: Sync.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36442

    Last Modified: 21 Nov 2024

    An issue was discovered in the beef crate before 0.5.0 for Rust. beef::Cow has no Sync bound on its Send trait.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2020-36443

    Last Modified: 21 Nov 2024

    An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36444

    Last Modified: 21 Nov 2024

    An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<RC, T> without trait bounds on RC.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36445

    Last Modified: 21 Nov 2024

    An issue was discovered in the convec crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for ConVec<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36446

    Last Modified: 21 Nov 2024

    An issue was discovered in the signal-simple crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for SyncChannel<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36447

    Last Modified: 21 Nov 2024

    An issue was discovered in the v9 crate through 2020-12-18 for Rust. There is an unconditional implementation of Sync for SyncRef<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36448

    Last Modified: 21 Nov 2024

    An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36449

    Last Modified: 21 Nov 2024

    An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36450

    Last Modified: 21 Nov 2024

    An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36451

    Last Modified: 21 Nov 2024

    An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2020-36452

    Last Modified: 21 Nov 2024

    An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36453

    Last Modified: 21 Nov 2024

    An issue was discovered in the scottqueue crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for Queue<T>.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36454

    Last Modified: 21 Nov 2024

    An issue was discovered in the parc crate through 2020-11-14 for Rust. LockWeak<T> has an unconditional implementation of Send without trait bounds on T.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36455

    Last Modified: 21 Nov 2024

    An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Sync.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36456

    Last Modified: 21 Nov 2024

    An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36457

    Last Modified: 21 Nov 2024

    An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36458

    Last Modified: 21 Nov 2024

    An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36459

    Last Modified: 21 Nov 2024

    An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36460

    Last Modified: 21 Nov 2024

    An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36461

    Last Modified: 21 Nov 2024

    An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36462

    Last Modified: 21 Nov 2024

    An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.

    Published: 8 Aug 2021
    8.1
    High

    CVE-2020-36463

    Last Modified: 21 Nov 2024

    An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.

    Published: 8 Aug 2021
    7.5
    High

    CVE-2020-36464

    Last Modified: 21 Nov 2024

    An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire underlying Vec without considering whether it has already been partially consumed.

    Published: 8 Aug 2021
    7.5
    High

    CVE-2020-36465

    Last Modified: 21 Nov 2024

    An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro to extend lifetimes.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36466

    Last Modified: 21 Nov 2024

    An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36467

    Last Modified: 21 Nov 2024

    An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr::get returns more than one mutable reference to the same object.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36468

    Last Modified: 21 Nov 2024

    An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr::write performs non-atomic write operations on an underlying pointer.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36469

    Last Modified: 21 Nov 2024

    An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send and Sync are implemented unconditionally.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36470

    Last Modified: 21 Nov 2024

    An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36471

    Last Modified: 21 Nov 2024

    An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2020-36472

    Last Modified: 21 Nov 2024

    An issue was discovered in the max7301 crate before 0.2.0 for Rust. The ImmediateIO and TransactionalIO types implement Sync for all Expander<EI> types that they contain.

    Published: 8 Aug 2021
    6.1
    Medium

    CVE-2021-38186

    Last Modified: 21 Nov 2024

    An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38187

    Last Modified: 21 Nov 2024

    An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a *u64.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38188

    Last Modified: 21 Nov 2024

    An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.length()) is used unsafely.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38189

    Last Modified: 21 Nov 2024

    An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.

    Published: 8 Aug 2021
    9.8
    Critical

    CVE-2021-38190

    Last Modified: 21 Nov 2024

    An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it does not ensure that the number of elements is equal to the product of the row count and column count.

    Published: 8 Aug 2021
    5.9
    Medium

    CVE-2021-38191

    Last Modified: 21 Nov 2024

    An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the wrong thread.

    Published: 8 Aug 2021
    7.5
    High

    CVE-2021-38192

    Last Modified: 21 Nov 2024

    An issue was discovered in the prost-types crate before 0.8.0 for Rust. An overflow can occur during conversion from Timestamp to SystemTime.

    Published: 8 Aug 2021