{"id":"CVE-2020-36205","aliases":["GHSA-c8hq-x4mm-p6q6","RUSTSEC-2020-0097"],"url":"https://o3.security/vulnerability/CVE-2020-36205","summary":"Memory handling issues in xcb","details":"An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of the public ptr field, a use-after-free or double-free can occur.","published":"2021-01-26T18:15:55.707Z","modified":"2026-03-14T10:29:26.563374Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00401,"percentile":0.33501,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"crates.io","name":"xcb","fixedVersion":"1.0.0"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://rustsec.org/advisories/RUSTSEC-2020-0097.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36205"},{"type":"WEB","url":"https://github.com/rtbo/rust-xcb/issues/93"},{"type":"WEB","url":"https://github.com/rust-x-bindings/rust-xcb/issues/93"},{"type":"PACKAGE","url":"https://github.com/rtbo/rust-xcb"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-14T10:29:26.563374Z"}}