Skip to content
Noroxi

jruby records

5 published records for vendor jruby.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

5 records
  • CVE-2009-4123
    30Monitor

    The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.

    HighCVSS 7.5No exploitEPSS 1%

    jruby · jruby-opensslDec 12, 2023

  • JRuby-OpenSSL has hostname verification disabled by default

    MediumCVSS 5.7No exploitEPSS 0%

    jruby · jrubyMay 7, 2025

  • CVE-2011-4838
    21Monitor

    JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-depen

    MediumCVSS 5.0No exploitEPSS 4%

    jruby · jrubyDec 29, 2011

  • CVE-2012-5370
    21Monitor

    JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent a

    MediumCVSS 5.0No exploitEPSS 2%

    jruby · jrubyNov 28, 2012

  • CVE-2010-1330
    18Monitor

    The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-

    MediumCVSS 4.3No exploitEPSS 2%

    jruby · jrubyNov 23, 2012