Known vulnerabilities in rust-lsd
Vendor:
Fedoraproject
Software:
rust-lsd
Software CPE:
cpe:2.3:o:fedoraproject:rust-lsd:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
10
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (10)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU143594 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-5917 |
CWE-78 | High | 1.2.0-8.el9, 1.2.0-8.el10_2, 1.2.0-8.el10_3, 1.2.0-8.fc43, 1.2.0-8.fc44 | 16.08.2026 |
SB20260816530 SB2026081711 SB2026081712 and 7 more |
||
| #VU138491 - Improper Validation of Certificate with Host Mismatch CVE-2026-53583 |
CWE-297 | Medium | 1.2.0-8.el9, 1.2.0-8.el10_2, 1.2.0-8.el10_3, 1.2.0-8.fc43, 1.2.0-8.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 9 more |
||
| #VU138490 - Insufficiently Protected Credentials CVE-2026-53586 |
CWE-522 | Medium | 1.2.0-8.el9, 1.2.0-8.el10_2, 1.2.0-8.el10_3, 1.2.0-8.fc43, 1.2.0-8.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-53584 |
CWE-22 | Low | 1.2.0-8.el9, 1.2.0-8.el10_2, 1.2.0-8.el10_3, 1.2.0-8.fc43, 1.2.0-8.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138487 - Out-of-bounds read CVE-2026-53587 |
CWE-125 | Medium | 1.2.0-8.el9, 1.2.0-8.el10_2, 1.2.0-8.el10_3, 1.2.0-8.fc43, 1.2.0-8.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU138485 - Allocation of Resources Without Limits or Throttling CVE-2026-53585 |
CWE-770 | Medium | 1.2.0-8.el9, 1.2.0-8.el10_2, 1.2.0-8.el10_3, 1.2.0-8.fc43, 1.2.0-8.fc44 | 20.07.2026 |
SB2026072079 SB2026072444 SB2026072445 and 10 more |
||
| #VU122823 - Type confusion CVE-2026-25537 |
CWE-843 | Medium | 1.2.0-3.fc42, 1.2.0-3.fc43, 1.2.0-3.fc44, 1.2.0-3.fc45 | 13.02.2026 |
SB2026021365 SB2026021366 SB2026021367 and 4 more |
||
| #VU86202 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-24575 |
CWE-835 | Medium | 1.0.0-3.fc38, 1.0.0-3.fc39, 1.0.0-3.fc40, 1.0.0-3.fc41 | 07.02.2024 |
SB2024020715 SB2024020801 SB2024020863 and 15 more |
||
| #VU86201 - Heap-based Buffer Overflow CVE-2024-24577 |
CWE-122 | High | 1.0.0-3.fc38, 1.0.0-3.fc39, 1.0.0-3.fc40, 1.0.0-3.fc41 | 07.02.2024 |
SB2024020715 SB2024020801 SB2024020863 and 29 more |
||
| #VU59898 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2022-21658 |
CWE-362 | High | 0.20.1-8.fc34, 0.20.1-8.fc35, 0.20.1-8.fc36 | 21.01.2022 |
SB2022012101 SB2022051149 SB2022031433 and 17 more |