Vulnerabilities > CVE-2021-27377 - Use After Free vulnerability in Yottadb

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
yottadb
CWE-416

Summary

An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free.

Vulnerable Configurations

Part Description Count
Application
Yottadb
4

Common Weakness Enumeration (CWE)