Перейти к содержимому
Noroxi

Записи rubygems

35 опубликованных записей вендора rubygems.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
80 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

35 записей
  • CVE-2017-0903
    44В плане

    RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 16 %

    rubygems · rubygems11 окт. 2017 г.

  • CVE-2017-0899
    42В плане

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    rubygems · rubygems31 авг. 2017 г.

  • CVE-2018-1000076
    40В плане

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    rubygems · rubygems13 мар. 2018 г.

  • CVE-2017-0901
    39Наблюдать

    RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any f

    ВысокаяCVSS 7,5Proof of conceptEPSS 29 %

    rubygems · rubygems31 авг. 2017 г.

  • CVE-2024-21654
    39Наблюдать

    rubygems.org MFA Bypass through password reset function could allow account takeover

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    rubygems · rubygems.org12 янв. 2024 г.

  • CVE-2019-8324
    36Наблюдать

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    rubygems · rubygems17 июн. 2019 г.

  • CVE-2022-36073
    35Наблюдать

    RubyGems allows creation of users with arbitrary unverified emails

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    rubygems · rubygems7 сент. 2022 г.

  • CVE-2013-0269
    34Наблюдать

    The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resourc

    ВысокаяCVSS 7,5Proof of conceptEPSS 14 %

    rubygems · json gem12 февр. 2013 г.

  • CVE-2017-0900
    33Наблюдать

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against Ruby

    ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %

    rubygems · rubygems31 авг. 2017 г.

  • CVE-2017-0902
    33Наблюдать

    RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client

    ВысокаяCVSS 8,1Эксплойта нетEPSS 5 %

    rubygems · rubygems31 авг. 2017 г.

  • CVE-2018-1000074
    32Наблюдать

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    rubygems · rubygems13 мар. 2018 г.

  • CVE-2018-1000073
    31Наблюдать

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    rubygems · rubygems13 мар. 2018 г.

  • CVE-2018-1000075
    31Наблюдать

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    rubygems · rubygems13 мар. 2018 г.

  • CVE-2012-2140
    31Наблюдать

    The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) e

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    rubygems · mail gem18 июл. 2012 г.

  • CVE-2013-2616
    31Наблюдать

    lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    rubygems · mini magick20 мар. 2013 г.

  • CVE-2013-1875
    31Наблюдать

    command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    rubygems · command wrap20 мар. 2013 г.

  • CVE-2019-8321
    31Наблюдать

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    rubygems · rubygems17 июн. 2019 г.

  • CVE-2019-8325
    31Наблюдать

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    rubygems · rubygems17 июн. 2019 г.

  • CVE-2019-8323
    31Наблюдать

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    rubygems · rubygems17 июн. 2019 г.

  • CVE-2019-8322
    31Наблюдать

    An issue was discovered in RubyGems 2.6 and later through 3.0.2.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    rubygems · rubygems17 июн. 2019 г.

  • CVE-2013-2615
    31Наблюдать

    lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    rubygems · fastreader20 мар. 2013 г.

  • CVE-2022-29176
    31Наблюдать

    Unauthorized gem takeover for some gems on rubygems.org

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    rubygems · rubygems.org5 мая 2022 г.

  • CVE-2019-8320
    30Наблюдать

    A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2.

    ВысокаяCVSS 7,4Эксплойта нетEPSS 4 %

    rubygems · rubygems6 июн. 2019 г.

  • CVE-2022-29218
    30Наблюдать

    Unauthorized takeover for new versions of some platform-specific gems

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    rubygems · rubygems.org12 мая 2022 г.

  • CVE-2023-40165
    30Наблюдать

    Unauthorized gem replacement for full names ending in numbers on rubygems.org

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    rubygems · rubygems.org17 авг. 2023 г.