rubyzip project records
3 published records for vendor rubyzip project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-1000544No exploit | rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arubyzip project · rubyzip · CWE-59 | Critical9.8 | — | 4.4% | Jun 26, 2018 |
40Plan | CVE-2017-5946No exploit | The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability.rubyzip project · rubyzip · CWE-22 | Critical9.8 | — | 3.4% | Feb 27, 2017 |
22Monitor | CVE-2019-16892No exploit | In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can berubyzip project · rubyzip | Medium5.5 | — | 1.6% | Sep 25, 2019 |
- CVE-2018-100054440Plan
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write a
CriticalCVSS 9.8No exploitEPSS 4%rubyzip project · rubyzipJun 26, 2018
- CVE-2017-594640Plan
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability.
CriticalCVSS 9.8No exploitEPSS 3%rubyzip project · rubyzipFeb 27, 2017
- CVE-2019-1689222Monitor
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be
MediumCVSS 5.5No exploitEPSS 2%rubyzip project · rubyzipSep 25, 2019