2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-35874HIGH8.1An issue was discovered in the internment crate through 2020-05-28 for Rust. ArcIntern::drop has a race condition and re...
CVE-2020-35873CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs ...
CVE-2020-35872CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) t...
CVE-2020-35871HIGH8.1An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API d...
CVE-2020-35870CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API u...
CVE-2020-35869CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::tr...
CVE-2020-35868CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotificati...
CVE-2020-35867CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module.
CVE-2020-35866CRITICAL9.8An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCurso...
CVE-2020-35865HIGH7.5An issue was discovered in the os_str_bytes crate before 2.0.0 for Rust. It has false expectations about char::from_u32_...
CVE-2020-35864HIGH7.5An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can trans...
CVE-2020-35863CRITICAL9.8An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execut...
CVE-2020-35862CRITICAL9.8An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-fre...
CVE-2020-35861HIGH7.5An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown me...
CVE-2020-35860CRITICAL9.8An issue was discovered in the cbox crate through 2020-03-19 for Rust. The CBox API allows dereferencing raw pointers wi...
CVE-2020-35859CRITICAL9.1An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. G...
CVE-2020-35858CRITICAL9.8An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, caus...
CVE-2020-35857HIGH7.5An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled...
CVE-2020-35928MEDIUM4.7An issue was discovered in the concread crate before 0.2.6 for Rust. Attackers can cause an ARCache<K,V> data race by se...
CVE-2020-35927MEDIUM5.5An issue was discovered in the thex crate through 2020-12-08 for Rust. Thex<T> allows cross-thread data races of non-Sen...
CVE-2020-35926CRITICAL9.8An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha)...
CVE-2020-35925MEDIUM5.5An issue was discovered in the magnetic crate before 2.0.1 for Rust. MPMCConsumer and MPMCProducer allow cross-thread se...
CVE-2020-35924MEDIUM5.5An issue was discovered in the try-mutex crate before 0.3.0 for Rust. TryMutex<T> allows cross-thread sending of a non-S...
CVE-2020-35923MEDIUM5.5An issue was discovered in the ordered-float crate before 1.1.1 and 2.x before 2.0.1 for Rust. A NotNan value can contai...
CVE-2020-35922MEDIUM5.5An issue was discovered in the mio crate before 0.7.6 for Rust. It has false expectations about the std::net::SocketAddr...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now