İçeriğe atla
Noroxi

ruby-lang kayıtları

ruby-lang üreticisine ait 138 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
3 · %2,2
Pre-auth RCE
20
Düzeltme kaydı olan
%89,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

138 kayıt
  • CVE-2017-17405
    57Planlayın

    Ruby before 2.4.3 allows Net::FTP command injection.

    YüksekCVSS 8,8Kavram kanıtıEPSS %74

    ruby-lang · ruby15 Ara 2017

  • CVE-2008-3656
    52Planlayın

    Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick i

    YüksekCVSS 7,8SilahlaştırılmışEPSS %70

    ruby-lang · ruby12 Ağu 2008

  • CVE-2021-28966
    47Planlayın

    In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.

    YüksekCVSS 7,5İstismar yokEPSS %57

    ruby-lang · ruby30 Tem 2021

  • CVE-2018-16395
    42Planlayın

    An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3

    KritikCVSS 9,8İstismar yokEPSS %11

    ruby-lang · openssl16 Kas 2018

  • CVE-2017-14064
    42Planlayın

    Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.

    KritikCVSS 9,8İstismar yokEPSS %9

    ruby-lang · ruby31 Ağu 2017

  • CVE-2016-2337
    41Planlayın

    Type confusion exists in _cancel_eval Ruby's TclTkIp class method.

    KritikCVSS 9,8İstismar yokEPSS %6

    ruby-lang · ruby6 Oca 2017

  • CVE-2017-17790
    41Planlayın

    The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demons

    KritikCVSS 9,8İstismar yokEPSS %6

    ruby-lang · ruby20 Ara 2017

  • CVE-2016-2339
    41Planlayın

    An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby.

    KritikCVSS 9,8İstismar yokEPSS %5

    ruby-lang · ruby6 Oca 2017

  • CVE-2008-2663
    41Planlayın

    Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8

    KritikCVSS 10,0İstismar yokEPSS %4

    ruby-lang · ruby24 Haz 2008

  • CVE-2008-2662
    41Planlayın

    Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.

    KritikCVSS 10,0İstismar yokEPSS %4

    ruby-lang · ruby24 Haz 2008

  • CVE-2009-4124
    41Planlayın

    Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to

    KritikCVSS 10,0İstismar yokEPSS %4

    ruby-lang · ruby11 Ara 2009

  • CVE-2013-1948
    41Planlayın

    converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a

    KritikCVSS 10,0İstismar yokEPSS %2

    rob westgeest · md2pdf25 Nis 2013

  • CVE-2017-10784
    40Planlayın

    The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers t

    YüksekCVSS 8,8İstismar yokEPSS %16

    ruby-lang · ruby19 Eyl 2017

  • CVE-2021-41816
    40Planlayın

    CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platfor

    KritikCVSS 9,8İstismar yokEPSS %5

    ruby-lang · cgi6 Şub 2022

  • CVE-2016-2338
    40Planlayın

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    ruby-lang · ruby28 Eyl 2022

  • CVE-2016-2336
    40Planlayın

    Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface.

    KritikCVSS 9,8İstismar yokEPSS %3

    ruby-lang · ruby6 Oca 2017

  • CVE-2017-9225
    40Planlayın

    An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5.

    KritikCVSS 9,8İstismar yokEPSS %3

    php · php24 May 2017

  • CVE-2022-28738
    40Planlayın

    A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.

    KritikCVSS 9,8İstismar yokEPSS %3

    ruby-lang · ruby9 May 2022

  • CVE-2011-4121
    40Planlayın

    The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used fo

    KritikCVSS 9,8İstismar yokEPSS %3

    ruby-lang · ruby26 Kas 2019

  • CVE-2024-27280
    40Planlayın

    A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.

    KritikCVSS 9,8İstismar yokEPSS %2

    14 May 2024

  • CVE-2017-11465
    40Planlayın

    The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possi

    KritikCVSS 9,8İstismar yokEPSS %2

    ruby-lang · ruby19 Tem 2017

  • CVE-2018-8780
    39İzleyin

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries an

    KritikCVSS 9,1İstismar yokEPSS %10

    ruby-lang · ruby3 Nis 2018

  • CVE-2017-0898
    39İzleyin

    Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus val

    KritikCVSS 9,1İstismar yokEPSS %10

    ruby-lang · ruby15 Eyl 2017

  • CVE-2013-1933
    38İzleyin

    The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context

    KritikCVSS 9,3İstismar yokEPSS %2

    documentcloud · karteek-docsplit25 Nis 2013

  • CVE-2013-4164
    37İzleyin

    Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 4

    OrtaCVSS 6,8SilahlaştırılmışEPSS %35

    ruby-lang · ruby23 Kas 2013