rusqlite
crates.io15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting rusqlitepage 1 of 1
- CVE-2020-35866CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor.
- CVE-2020-35867CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module.
- CVE-2020-35868CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotification.
- CVE-2020-35869CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.
- CVE-2020-35870CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.
- CVE-2020-35871HIGHCVSS 8.1EG 8.1fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API data race.
- CVE-2020-35872CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) type.
- CVE-2020-35873CRITICALCVSS 9.8EG 9.8fixed in 0.23.02020-12-31
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free.
- CVE-2021-45713HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free.
- CVE-2021-45714HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free.
- CVE-2021-45715HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free.
- CVE-2021-45716HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free.
- CVE-2021-45717HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free.
- CVE-2021-45718HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free.
- CVE-2021-45719HIGHCVSS 7.5EG 7.5fixed in 0.25.4 or 0.26.2, by version range2021-12-26
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free.
Check whether rusqlite is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for rusqlite CVEs against the assets you own.
Book a Demo →