CVE-2015-20001 describes a memory safety vulnerability in the Rust standard library, specifically affecting BinaryHeap in Rust versions prior to 1.2.0. When element comparisons within sift_up or sift_down_range panic, the heap enters an inconsistent state, leading to the dropping of zeroed memory as an arbitrary type. This flaw carries a CVSS v3.1 score of 7.5 (High), indicating a network-exploitable vulnerability with low attack complexity and high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:rust:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.