Записи ruby-lang
138 опубликованных записей вендора ruby-lang.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 2,2 %
- Pre-auth RCE
- 20
- С записью об исправлении
- 89,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-400 Uncontrolled Resource Consumption8
- CWE-399 Resource Management Errors7
- CWE-1333 Inefficient Regular Expression Complexity7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
138 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2017-17405Proof of concept | Ruby before 2.4.3 allows Net::FTP command injection.ruby-lang · ruby · CWE-78 | Высокая8,8 | — | 73,8 % | 15 дек. 2017 г. |
52В плане | CVE-2008-3656Готовый эксплойт | Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick iruby-lang · ruby · CWE-399 | Высокая7,8 | — | 70,2 % | 12 авг. 2008 г. |
47В плане | CVE-2021-28966Эксплойта нет | In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.ruby-lang · ruby · CWE-22 | Высокая7,5 | — | 57,1 % | 30 июл. 2021 г. |
42В плане | CVE-2018-16395Эксплойта нет | An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3ruby-lang · openssl | Критическая9,8 | — | 10,7 % | 16 нояб. 2018 г. |
42В плане | CVE-2017-14064Эксплойта нет | Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.ruby-lang · ruby · CWE-119 | Критическая9,8 | — | 9,4 % | 31 авг. 2017 г. |
41В плане | CVE-2016-2337Эксплойта нет | Type confusion exists in _cancel_eval Ruby's TclTkIp class method.ruby-lang · ruby | Критическая9,8 | — | 6,2 % | 6 янв. 2017 г. |
41В плане | CVE-2017-17790Эксплойта нет | The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonsruby-lang · ruby · CWE-74 | Критическая9,8 | — | 5,9 % | 20 дек. 2017 г. |
41В плане | CVE-2016-2339Эксплойта нет | An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby.ruby-lang · ruby · CWE-119 | Критическая9,8 | — | 5,2 % | 6 янв. 2017 г. |
41В плане | CVE-2008-2663Эксплойта нет | Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8ruby-lang · ruby · CWE-190 | Критическая10,0 | — | 4,5 % | 24 июн. 2008 г. |
41В плане | CVE-2008-2662Эксплойта нет | Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.ruby-lang · ruby · CWE-189 | Критическая10,0 | — | 4,3 % | 24 июн. 2008 г. |
41В плане | CVE-2009-4124Эксплойта нет | Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to ruby-lang · ruby · CWE-119 | Критическая10,0 | — | 3,9 % | 11 дек. 2009 г. |
41В плане | CVE-2013-1948Эксплойта нет | converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in arob westgeest · md2pdf | Критическая10,0 | — | 2,2 % | 25 апр. 2013 г. |
40В плане | CVE-2017-10784Эксплойта нет | The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers truby-lang · ruby · CWE-287 | Высокая8,8 | — | 16,4 % | 19 сент. 2017 г. |
40В плане | CVE-2021-41816Эксплойта нет | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforruby-lang · cgi · CWE-190 | Критическая9,8 | — | 4,8 % | 6 февр. 2022 г. |
40В плане | CVE-2016-2338Proof of concept | An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby.ruby-lang · ruby · CWE-787 | Критическая9,8 | — | 4,7 % | 28 сент. 2022 г. |
40В плане | CVE-2016-2336Эксплойта нет | Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface.ruby-lang · ruby | Критическая9,8 | — | 3,3 % | 6 янв. 2017 г. |
40В плане | CVE-2017-9225Эксплойта нет | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5.php · php · CWE-787 | Критическая9,8 | — | 3,1 % | 24 мая 2017 г. |
40В плане | CVE-2022-28738Эксплойта нет | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.ruby-lang · ruby · CWE-415 | Критическая9,8 | — | 2,9 % | 9 мая 2022 г. |
40В плане | CVE-2011-4121Эксплойта нет | The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used foruby-lang · ruby · CWE-326 | Критическая9,8 | — | 2,5 % | 26 нояб. 2019 г. |
40В плане | CVE-2024-27280Эксплойта нет | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.CWE-120 | Критическая9,8 | — | 2,4 % | 14 мая 2024 г. |
40В плане | CVE-2017-11465Эксплойта нет | The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possiruby-lang · ruby · CWE-125 | Критическая9,8 | — | 1,7 % | 19 июл. 2017 г. |
39Наблюдать | CVE-2018-8780Эксплойта нет | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries anruby-lang · ruby · CWE-22 | Критическая9,1 | — | 9,7 % | 3 апр. 2018 г. |
39Наблюдать | CVE-2017-0898Эксплойта нет | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus valruby-lang · ruby · CWE-134 | Критическая9,1 | — | 9,7 % | 15 сент. 2017 г. |
38Наблюдать | CVE-2013-1933Эксплойта нет | The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows contextdocumentcloud · karteek-docsplit · CWE-78 | Критическая9,3 | — | 1,8 % | 25 апр. 2013 г. |
37Наблюдать | CVE-2013-4164Готовый эксплойт | Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 4ruby-lang · ruby · CWE-119 | Средняя6,8 | — | 35,0 % | 23 нояб. 2013 г. |
- CVE-2017-1740557В плане
Ruby before 2.4.3 allows Net::FTP command injection.
ВысокаяCVSS 8,8Proof of conceptEPSS 74 %ruby-lang · ruby15 дек. 2017 г.
- CVE-2008-365652В плане
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick i
ВысокаяCVSS 7,8Готовый эксплойтEPSS 70 %ruby-lang · ruby12 авг. 2008 г.
- CVE-2021-2896647В плане
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
ВысокаяCVSS 7,5Эксплойта нетEPSS 57 %ruby-lang · ruby30 июл. 2021 г.
- CVE-2018-1639542В плане
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %ruby-lang · openssl16 нояб. 2018 г.
- CVE-2017-1406442В плане
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %ruby-lang · ruby31 авг. 2017 г.
- CVE-2016-233741В плане
Type confusion exists in _cancel_eval Ruby's TclTkIp class method.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %ruby-lang · ruby6 янв. 2017 г.
- CVE-2017-1779041В плане
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demons
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %ruby-lang · ruby20 дек. 2017 г.
- CVE-2016-233941В плане
An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ruby-lang · ruby6 янв. 2017 г.
- CVE-2008-266341В плане
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %ruby-lang · ruby24 июн. 2008 г.
- CVE-2008-266241В плане
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %ruby-lang · ruby24 июн. 2008 г.
- CVE-2009-412441В плане
Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %ruby-lang · ruby11 дек. 2009 г.
- CVE-2013-194841В плане
converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %rob westgeest · md2pdf25 апр. 2013 г.
- CVE-2017-1078440В плане
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers t
ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %ruby-lang · ruby19 сент. 2017 г.
- CVE-2021-4181640В плане
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platfor
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ruby-lang · cgi6 февр. 2022 г.
- CVE-2016-233840В плане
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %ruby-lang · ruby28 сент. 2022 г.
- CVE-2016-233640В плане
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ruby-lang · ruby6 янв. 2017 г.
- CVE-2017-922540В плане
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %php · php24 мая 2017 г.
- CVE-2022-2873840В плане
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ruby-lang · ruby9 мая 2022 г.
- CVE-2011-412140В плане
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used fo
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ruby-lang · ruby26 нояб. 2019 г.
- CVE-2024-2728040В плане
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %14 мая 2024 г.
- CVE-2017-1146540В плане
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possi
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ruby-lang · ruby19 июл. 2017 г.
- CVE-2018-878039Наблюдать
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries an
КритическаяCVSS 9,1Эксплойта нетEPSS 10 %ruby-lang · ruby3 апр. 2018 г.
- CVE-2017-089839Наблюдать
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus val
КритическаяCVSS 9,1Эксплойта нетEPSS 10 %ruby-lang · ruby15 сент. 2017 г.
- CVE-2013-193338Наблюдать
The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %documentcloud · karteek-docsplit25 апр. 2013 г.
- CVE-2013-416437Наблюдать
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 4
СредняяCVSS 6,8Готовый эксплойтEPSS 35 %ruby-lang · ruby23 нояб. 2013 г.