Rusqlite
Vendor:
First CVE: Dec 31, 2020 · Active for 5 years
15
Total CVEs
More Total CVEs than 93% of tracked products
7.5
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rusqlite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2020
5 years ago
Most Recent CVE
Dec 26, 2021
1,675 days ago
CVE Severity & Scoring
Rusqlite15 CVEs
53%
47%
All CVEs353,173 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None15 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35869CRITICAL An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings. | Dec 31, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-35872CRITICAL An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) type. | Dec 31, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-35868CRITICAL An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotification. | Dec 31, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-35867CRITICAL An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module. | Dec 31, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-35866CRITICAL An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor. | Dec 31, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-35873CRITICAL An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free. | Dec 31, 2020 | 9.8 | 28 | NO | NO |
CVE-2021-45719HIGH An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free. | Dec 26, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-45718HIGH An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free. | Dec 26, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-45716HIGH An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free. | Dec 26, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-45715HIGH An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free. | Dec 26, 2021 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Rusqlite
Top CWEs
Versions
No cataloged versions.