Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 20

Количество 20

fstec логотип

BDU:2026-06110

12 месяцев назад

Уязвимость библиотеки tracing-subscriber, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-58160

12 месяцев назад

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

EPSS: Низкий
redhat логотип

CVE-2025-58160

12 месяцев назад

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-58160

12 месяцев назад

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

EPSS: Низкий
msrc логотип

CVE-2025-58160

7 месяцев назад

Tracing logging user input may result in poisoning logs with ANSI escape sequences

EPSS: Низкий
debian логотип

CVE-2025-58160

12 месяцев назад

tracing is a framework for instrumenting Rust programs to collect stru ...

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21074-1

около 1 месяца назад

Security update for loupe

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20180-1

6 месяцев назад

Security update for python-maturin

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4091-1

9 месяцев назад

Security update for cargo-packaging, rust-bindgen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3869-1

9 месяцев назад

Security update for himmelblau

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03082-1

11 месяцев назад

Security update for python-maturin

EPSS: Низкий
github логотип

GHSA-xwfj-jgwm-7wp5

12 месяцев назад

Tracing logging user input may result in poisoning logs with ANSI escape sequences

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21134-1

около 2 месяцев назад

Security update for glycin-loaders

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20026-1

7 месяцев назад

Security update for python-uv

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20114-1

9 месяцев назад

Security update for himmelblau

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20060-1

7 месяцев назад

Security update for cargo-c

EPSS: Низкий
suse-cvrf логотип

openSUSE-FU-2026:20453-1

4 месяца назад

Feature update for himmelblau

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1361-1

4 месяца назад

Security update for himmelblau

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2832-1

около 1 месяца назад

Security update for rustup

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2831-1

около 1 месяца назад

Security update for rustup

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-06110

Уязвимость библиотеки tracing-subscriber, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 4.3
0%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

0%
Низкий
12 месяцев назад
redhat логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

CVSS3: 3.1
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2025-58160

Tracing logging user input may result in poisoning logs with ANSI escape sequences

0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect stru ...

0%
Низкий
12 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21074-1

Security update for loupe

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20180-1

Security update for python-maturin

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4091-1

Security update for cargo-packaging, rust-bindgen

0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3869-1

Security update for himmelblau

0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03082-1

Security update for python-maturin

0%
Низкий
11 месяцев назад
github логотип
GHSA-xwfj-jgwm-7wp5

Tracing logging user input may result in poisoning logs with ANSI escape sequences

0%
Низкий
12 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21134-1

Security update for glycin-loaders

около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20026-1

Security update for python-uv

7 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20114-1

Security update for himmelblau

9 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20060-1

Security update for cargo-c

7 месяцев назад
suse-cvrf логотип
openSUSE-FU-2026:20453-1

Feature update for himmelblau

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1361-1

Security update for himmelblau

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2832-1

Security update for rustup

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2831-1

Security update for rustup

около 1 месяца назад

Уязвимостей на страницу