İçeriğe atla
Noroxi

rubygems kayıtları

rubygems üreticisine ait 35 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%80
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

35 kayıt
  • CVE-2017-0903
    44Planlayın

    RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %16

    rubygems · rubygems11 Eki 2017

  • CVE-2017-0899
    42Planlayın

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.

    KritikCVSS 9,8İstismar yokEPSS %11

    rubygems · rubygems31 Ağu 2017

  • CVE-2018-1000076
    40Planlayın

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    KritikCVSS 9,8İstismar yokEPSS %3

    rubygems · rubygems13 Mar 2018

  • CVE-2017-0901
    39İzleyin

    RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any f

    YüksekCVSS 7,5Kavram kanıtıEPSS %29

    rubygems · rubygems31 Ağu 2017

  • CVE-2024-21654
    39İzleyin

    rubygems.org MFA Bypass through password reset function could allow account takeover

    KritikCVSS 9,8İstismar yokEPSS %0

    rubygems · rubygems.org12 Oca 2024

  • CVE-2019-8324
    36İzleyin

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    YüksekCVSS 8,8İstismar yokEPSS %3

    rubygems · rubygems17 Haz 2019

  • CVE-2022-36073
    35İzleyin

    RubyGems allows creation of users with arbitrary unverified emails

    YüksekCVSS 8,8İstismar yokEPSS %1

    rubygems · rubygems7 Eyl 2022

  • CVE-2013-0269
    34İzleyin

    The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourc

    YüksekCVSS 7,5Kavram kanıtıEPSS %13

    rubygems · json gem12 Şub 2013

  • CVE-2017-0902
    33İzleyin

    RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client

    YüksekCVSS 8,1İstismar yokEPSS %5

    rubygems · rubygems31 Ağu 2017

  • CVE-2017-0900
    32İzleyin

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Ruby

    YüksekCVSS 7,5İstismar yokEPSS %8

    rubygems · rubygems31 Ağu 2017

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    YüksekCVSS 7,8İstismar yokEPSS %3

    rubygems · rubygems13 Mar 2018

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    YüksekCVSS 7,5İstismar yokEPSS %5

    rubygems · rubygems13 Mar 2018

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    YüksekCVSS 7,5İstismar yokEPSS %5

    rubygems · rubygems13 Mar 2018

  • CVE-2012-2140
    31İzleyin

    The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) e

    YüksekCVSS 7,5İstismar yokEPSS %4

    rubygems · mail gem18 Tem 2012

  • CVE-2013-2616
    31İzleyin

    lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a

    YüksekCVSS 7,5İstismar yokEPSS %4

    rubygems · mini magick20 Mar 2013

  • CVE-2013-1875
    31İzleyin

    command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or

    YüksekCVSS 7,5İstismar yokEPSS %4

    rubygems · command wrap20 Mar 2013

  • CVE-2019-8321
    31İzleyin

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    YüksekCVSS 7,5İstismar yokEPSS %3

    rubygems · rubygems17 Haz 2019

  • CVE-2019-8325
    31İzleyin

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    YüksekCVSS 7,5İstismar yokEPSS %3

    rubygems · rubygems17 Haz 2019

  • CVE-2019-8323
    31İzleyin

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    YüksekCVSS 7,5İstismar yokEPSS %3

    rubygems · rubygems17 Haz 2019

  • CVE-2019-8322
    31İzleyin

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    YüksekCVSS 7,5İstismar yokEPSS %3

    rubygems · rubygems17 Haz 2019

  • CVE-2013-2615
    31İzleyin

    lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters

    YüksekCVSS 7,5İstismar yokEPSS %2

    rubygems · fastreader20 Mar 2013

  • CVE-2022-29176
    31İzleyin

    Unauthorized gem takeover for some gems on rubygems.org

    YüksekCVSS 7,5İstismar yokEPSS %2

    rubygems · rubygems.org5 May 2022

  • CVE-2019-8320
    30İzleyin

    A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.

    YüksekCVSS 7,4İstismar yokEPSS %4

    rubygems · rubygems6 Haz 2019

  • CVE-2022-29218
    30İzleyin

    Unauthorized takeover for new versions of some platform-specific gems

    YüksekCVSS 7,5İstismar yokEPSS %1

    rubygems · rubygems.org12 May 2022

  • CVE-2023-40165
    30İzleyin

    Unauthorized gem replacement for full names ending in numbers on rubygems.org

    YüksekCVSS 7,5İstismar yokEPSS %0

    rubygems · rubygems.org17 Ağu 2023