{"id":"CVE-2021-38188","aliases":["RUSTSEC-2021-0068"],"url":"https://o3.security/vulnerability/CVE-2021-38188","summary":"Incorrect buffer size calculation in iced-x86","details":"An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.length()) is used unsafely.","published":"2021-08-25T20:55:47Z","modified":"2023-11-08T04:06:25.737471Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01275,"percentile":0.67732,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"crates.io","name":"iced-x86","fixedVersion":"1.11.0"}],"fix":{"url":"https://github.com/icedland/iced/commit/3c607a003e03b773108401d109167d1840487dce","label":"icedland/iced@3c607a0"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-38188"},{"type":"WEB","url":"https://github.com/icedland/iced/issues/168"},{"type":"WEB","url":"https://github.com/icedland/iced/commit/3c607a003e03b773108401d109167d1840487dce"},{"type":"PACKAGE","url":"https://github.com/icedland/iced"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0068.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:06:25.737471Z"}}