Unknown · CVSS Not scored
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the unicycle crate before 0.7.1 for Rust. PinSlab<T> and Unordered<T, S> do not have bounds on their Send and Sync traits.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire underlying Vec without considering whether it has already been partially consumed.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the cgc crate through 2020-12-10 for Rust. Ptr implements Send and Sync for all types.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs.
Published Aug 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the model crate through 2020-11-10 for Rust. The Shared data structure has an implementation of the Send and Sync traits without regard for the inner type.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the signal-simple crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for SyncChannel<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the chunky crate through 2020-08-25 for Rust. The Chunk API does not honor an alignment requirement.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SafeCurl before 0.9.2 has a DNS rebinding vulnerability.
Published Aug 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the libsbc crate before 0.1.5 for Rust. For Decoder<R>, it implements Send for any R: Read.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the appendix crate through 2020-11-15 for Rust. For the generic K and V type parameters, Send and Sync are implemented unconditionally.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the async-coap crate through 2020-12-08 for Rust. Send and Sync are implemented for ArcGuard<RC, T> without trait bounds on RC.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the convec crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for ConVec<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the ruspiro-singleton crate before 0.4.1 for Rust. In Singleton, Send and Sync do not have bounds checks.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the conqueue crate before 0.4.0 for Rust. There are unconditional implementations of Send and Sync for QueueSender<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the scottqueue crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for Queue<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the ticketed_lock crate before 0.3.0 for Rust. There are unconditional implementations of Send for ReadTicket<T> and WriteTicket<T>.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro to extend lifetimes.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Sync.
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().
Published Aug 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.
Published Aug 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the length of the TCP payload within the TCP checksum computation function. When the IP payload size is set to be smaller than the size of the IP header, the TCP checksum computation function may read out of bounds (a low-impact write-out-of-bounds is also possible).
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the ICMP checksum. When the IP payload size is set to be smaller than the size of the IP header, the ICMP checksum computation function may read out of bounds, causing a Denial-of-Service.
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.)
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.
Published Aug 23, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Published Aug 31, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS command, injecting plaintext commands into an encrypted user session.
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.
Published Aug 17, 2021 · Updated Aug 4, 2024
Critical · CVSS 9.6
An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Aug 11, 2021 · Updated Aug 4, 2024
High · CVSS 8.8
A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (Version V4.4), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions > V2.5 < V2.9.2), SIMATIC S7-1500 Software Controller (All versions > V2.5 < V21.9), TIM 1531 IRC (incl. SIPLUS NET variants) (Version V2.1). Due to an incorrect authorization check in the affected component, an attacker could extract information about access protected PLC program variables over port 102/tcp from an affected device when reading multiple attributes at once.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
Published Aug 12, 2021 · Updated Aug 4, 2024