Skip to content
Noroxi

rubyzip project records

3 published records for vendor rubyzip project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 18
  3. 19

Bar: total · dark part: CISA KEV.

All records

3 records
  • rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write a

    CriticalCVSS 9.8No exploitEPSS 4%

    rubyzip project · rubyzipJun 26, 2018

  • The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability.

    CriticalCVSS 9.8No exploitEPSS 3%

    rubyzip project · rubyzipFeb 27, 2017

  • In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be

    MediumCVSS 5.5No exploitEPSS 2%

    rubyzip project · rubyzipSep 25, 2019