Skip to content
Noroxi

rubygems records

35 published records for vendor rubygems.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

35 records
  • RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.

    CriticalCVSS 9.8No exploitEPSS 16%

    rubygems · rubygemsOct 11, 2017

  • RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.

    CriticalCVSS 9.8No exploitEPSS 11%

    rubygems · rubygemsAug 31, 2017

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    CriticalCVSS 9.8No exploitEPSS 3%

    rubygems · rubygemsMar 13, 2018

  • CVE-2017-0901
    39Monitor

    RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any f

    HighCVSS 7.5Proof of conceptEPSS 29%

    rubygems · rubygemsAug 31, 2017

  • rubygems.org MFA Bypass through password reset function could allow account takeover

    CriticalCVSS 9.8No exploitEPSS 0%

    rubygems · rubygems.orgJan 12, 2024

  • CVE-2019-8324
    36Monitor

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    HighCVSS 8.8No exploitEPSS 3%

    rubygems · rubygemsJun 17, 2019

  • RubyGems allows creation of users with arbitrary unverified emails

    HighCVSS 8.8No exploitEPSS 1%

    rubygems · rubygemsSep 7, 2022

  • CVE-2013-0269
    34Monitor

    The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourc

    HighCVSS 7.5Proof of conceptEPSS 13%

    rubygems · json gemFeb 12, 2013

  • CVE-2017-0902
    33Monitor

    RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client

    HighCVSS 8.1No exploitEPSS 5%

    rubygems · rubygemsAug 31, 2017

  • CVE-2017-0900
    32Monitor

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Ruby

    HighCVSS 7.5No exploitEPSS 8%

    rubygems · rubygemsAug 31, 2017

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    HighCVSS 7.8No exploitEPSS 3%

    rubygems · rubygemsMar 13, 2018

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    HighCVSS 7.5No exploitEPSS 5%

    rubygems · rubygemsMar 13, 2018

  • RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    HighCVSS 7.5No exploitEPSS 5%

    rubygems · rubygemsMar 13, 2018

  • CVE-2012-2140
    31Monitor

    The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) e

    HighCVSS 7.5No exploitEPSS 4%

    rubygems · mail gemJul 18, 2012

  • CVE-2013-2616
    31Monitor

    lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a

    HighCVSS 7.5No exploitEPSS 4%

    rubygems · mini magickMar 20, 2013

  • CVE-2013-1875
    31Monitor

    command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or

    HighCVSS 7.5No exploitEPSS 4%

    rubygems · command wrapMar 20, 2013

  • CVE-2019-8321
    31Monitor

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    HighCVSS 7.5No exploitEPSS 3%

    rubygems · rubygemsJun 17, 2019

  • CVE-2019-8325
    31Monitor

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    HighCVSS 7.5No exploitEPSS 3%

    rubygems · rubygemsJun 17, 2019

  • CVE-2019-8323
    31Monitor

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    HighCVSS 7.5No exploitEPSS 3%

    rubygems · rubygemsJun 17, 2019

  • CVE-2019-8322
    31Monitor

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    HighCVSS 7.5No exploitEPSS 3%

    rubygems · rubygemsJun 17, 2019

  • CVE-2013-2615
    31Monitor

    lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters

    HighCVSS 7.5No exploitEPSS 2%

    rubygems · fastreaderMar 20, 2013

  • Unauthorized gem takeover for some gems on rubygems.org

    HighCVSS 7.5No exploitEPSS 2%

    rubygems · rubygems.orgMay 5, 2022

  • CVE-2019-8320
    30Monitor

    A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.

    HighCVSS 7.4No exploitEPSS 4%

    rubygems · rubygemsJun 6, 2019

  • Unauthorized takeover for new versions of some platform-specific gems

    HighCVSS 7.5No exploitEPSS 1%

    rubygems · rubygems.orgMay 12, 2022

  • Unauthorized gem replacement for full names ending in numbers on rubygems.org

    HighCVSS 7.5No exploitEPSS 0%

    rubygems · rubygems.orgAug 17, 2023