Перейти к содержимому
Noroxi

Записи ruby-lang

138 опубликованных записей вендора ruby-lang.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
3 · 2,2 %
Pre-auth RCE
20
С записью об исправлении
89,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

138 записей
  • CVE-2017-17405
    57В плане

    Ruby before 2.4.3 allows Net::FTP command injection.

    ВысокаяCVSS 8,8Proof of conceptEPSS 74 %

    ruby-lang · ruby15 дек. 2017 г.

  • CVE-2008-3656
    52В плане

    Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick i

    ВысокаяCVSS 7,8Готовый эксплойтEPSS 70 %

    ruby-lang · ruby12 авг. 2008 г.

  • CVE-2021-28966
    47В плане

    In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 57 %

    ruby-lang · ruby30 июл. 2021 г.

  • CVE-2018-16395
    42В плане

    An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    ruby-lang · openssl16 нояб. 2018 г.

  • CVE-2017-14064
    42В плане

    Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    ruby-lang · ruby31 авг. 2017 г.

  • CVE-2016-2337
    41В плане

    Type confusion exists in _cancel_eval Ruby's TclTkIp class method.

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    ruby-lang · ruby6 янв. 2017 г.

  • CVE-2017-17790
    41В плане

    The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demons

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    ruby-lang · ruby20 дек. 2017 г.

  • CVE-2016-2339
    41В плане

    An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    ruby-lang · ruby6 янв. 2017 г.

  • CVE-2008-2663
    41В плане

    Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    ruby-lang · ruby24 июн. 2008 г.

  • CVE-2008-2662
    41В плане

    Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    ruby-lang · ruby24 июн. 2008 г.

  • CVE-2009-4124
    41В плане

    Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    ruby-lang · ruby11 дек. 2009 г.

  • CVE-2013-1948
    41В плане

    converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    rob westgeest · md2pdf25 апр. 2013 г.

  • CVE-2017-10784
    40В плане

    The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers t

    ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %

    ruby-lang · ruby19 сент. 2017 г.

  • CVE-2021-41816
    40В плане

    CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platfor

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    ruby-lang · cgi6 февр. 2022 г.

  • CVE-2016-2338
    40В плане

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby.

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    ruby-lang · ruby28 сент. 2022 г.

  • CVE-2016-2336
    40В плане

    Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ruby-lang · ruby6 янв. 2017 г.

  • CVE-2017-9225
    40В плане

    An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    php · php24 мая 2017 г.

  • CVE-2022-28738
    40В плане

    A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ruby-lang · ruby9 мая 2022 г.

  • CVE-2011-4121
    40В плане

    The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used fo

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ruby-lang · ruby26 нояб. 2019 г.

  • CVE-2024-27280
    40В плане

    A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    14 мая 2024 г.

  • CVE-2017-11465
    40В плане

    The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possi

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    ruby-lang · ruby19 июл. 2017 г.

  • CVE-2018-8780
    39Наблюдать

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries an

    КритическаяCVSS 9,1Эксплойта нетEPSS 10 %

    ruby-lang · ruby3 апр. 2018 г.

  • CVE-2017-0898
    39Наблюдать

    Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus val

    КритическаяCVSS 9,1Эксплойта нетEPSS 10 %

    ruby-lang · ruby15 сент. 2017 г.

  • CVE-2013-1933
    38Наблюдать

    The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    documentcloud · karteek-docsplit25 апр. 2013 г.

  • CVE-2013-4164
    37Наблюдать

    Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 4

    СредняяCVSS 6,8Готовый эксплойтEPSS 35 %

    ruby-lang · ruby23 нояб. 2013 г.