Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

22,372 advisories

Loading
Delegate functions are missing `Send` bound Critical
GHSA-x4mq-m75f-mx8m was published for windows (Rust) Jun 17, 2022
KamilaBorowska
vec-const attempts to construct a Vec from a pointer to a const slice Moderate
GHSA-jmwx-r3gq-qq3p was published for vec-const (Rust) Jun 17, 2022
Memory Safety Issue when using `patch` or `merge` on `state` and assign the result back to `state` High
GHSA-3pp4-64mp-9cg9 was published for tremor-script (Rust) Jun 17, 2022
tower-http's improper validation of Windows paths could lead to directory traversal attack Moderate
GHSA-wwh2-r387-g5rm was published for tower-http (Rust) Jun 17, 2022
Data race in `Iter` and `IterMut` High
GHSA-9hpw-r23r-xgm5 was published for thread_local (Rust) Jun 17, 2022
`Read` on uninitialized buffer may cause UB ('tectonic_xdv' crate) High
GHSA-6692-8qqf-79jc was published for tectonic_xdv (Rust) Jun 17, 2022
Panic on incorrect date input to `simple_asn1` Moderate
GHSA-3m6f-3gfg-4x56 was published for simple_asn1 (Rust) Jun 17, 2022
saethlin
Miscomputed sha2 results when using AVX2 backend High
GHSA-xpww-g9jx-hp8r was published for sha2 (Rust) Jun 17, 2022
Threshold value is ignored (all shares are n=3) Low
GHSA-978j-88f3-p5j3 was published for shamir (Rust) Jun 17, 2022
Stack overflow in rustc_serialize when parsing deeply nested JSON Moderate
GHSA-2226-4v3c-cff8 was published for rustc-serialize (Rust) Jun 17, 2022
RustEmbed generated `get` method allows for directory traversal when reading files from disk Moderate
GHSA-cgw6-f3mj-h742 was published for rust-embed (Rust) Jun 17, 2022
Miscomputation when performing AES encryption in rust-crypto Critical
GHSA-jp3w-3q88-34cf was published for rust-crypto (Rust) Jun 17, 2022
Incorrect Lifetime Bounds on Closures in `rusqlite` High
GHSA-q89g-4vhh-mvvm was published for rusqlite (Rust) Jun 17, 2022
Optional `Deserialize` implementations lacking validation Moderate
GHSA-jf5h-cf95-w759 was published for raw-cpuid (Rust) Jun 17, 2022
A malicious coder can get unsound access to TCell or TLCell memory High
GHSA-9c9f-7x9p-4wqp was published for qcell (Rust) Jun 17, 2022
Window can read out of bounds if Read instance returns more bytes than buffer size High
GHSA-q579-9wp9-gfp2 was published for rdiff (Rust) Jun 17, 2022
Out-of-bounds write in nix::unistd::getgrouplist High
GHSA-wgrg-5h56-jg27 was published for nix (Rust) Jun 17, 2022
Use after free in Neon external buffers High
GHSA-8mj7-wxmc-f424 was published for neon (Rust) Jun 17, 2022
Aliased mutable references from `tls_rand` & `TlsWyRand` Moderate
GHSA-p6gj-gpc8-f8xw was published for nanorand (Rust) Jun 17, 2022
AtomicBucket<T> unconditionally implements Send/Sync Moderate
GHSA-3hxh-7jxm-59x4 was published for metrics-util (Rust) Jun 17, 2022
`mopa` is technically unsound High
GHSA-8mv5-7x95-7wcf was published for mopa (Rust) Jun 17, 2022
Deserialization functions pass uninitialized memory to user-provided Read High
GHSA-m325-rxjv-pwph was published for messagepack-rs (Rust) Jun 17, 2022
Use after free in lru crate High
GHSA-qqmc-hwqp-8g2w was published for lru (Rust) Jun 17, 2022
XML External Entity Reference in drools Critical
CVE-2021-41411 was published for org.drools:drools-core (Maven) Jun 17, 2022
wnicholson
Insufficiently Protected Credentials in PowerJob High
CVE-2020-28865 was published for com.github.kfcfans:powerjob (Maven) Jun 17, 2022
ProTip! Advisories are also available from the GraphQL API