servo CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

servo vulnerability overview

Aggregates CVE and security vulnerability intelligence across all servo-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk memory corruption and vendor risk csrf; exposure may include vendor impact memory corruption and vendor impact application crash in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-12224 Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname. [email protected] 5.1 0.15% 2025-05-30 2025-06-25
CVE-2018-25023 An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type. [email protected] 7.5 0.23% 2021-12-27 2024-11-21
CVE-2021-25900 An issue was discovered in the smallvec crate before 0.6.14 and 1.x before 1.6.1 for Rust. There is a heap-based buffer overflow in SmallVec::insert_many. [email protected] 9.8 0.55% 2021-01-26 2024-11-21
CVE-2019-15554 An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity. [email protected] 9.8 0.42% 2019-08-26 2024-11-21
CVE-2019-15551 An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity. [email protected] 9.8 0.43% 2019-08-26 2024-11-21
CVE-2018-20991 An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free. [email protected] 9.8 0.43% 2019-08-26 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence