ruby-lang kayıtları
ruby-lang üreticisine ait 138 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %2,2
- Pre-auth RCE
- 20
- Düzeltme kaydı olan
- %89,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-400 Uncontrolled Resource Consumption8
- CWE-399 Resource Management Errors7
- CWE-1333 Inefficient Regular Expression Complexity7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
138 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2017-17405Kavram kanıtı | Ruby before 2.4.3 allows Net::FTP command injection.ruby-lang · ruby · CWE-78 | Yüksek8,8 | — | %73,8 | 15 Ara 2017 |
52Planlayın | CVE-2008-3656Silahlaştırılmış | Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick iruby-lang · ruby · CWE-399 | Yüksek7,8 | — | %70,2 | 12 Ağu 2008 |
47Planlayın | CVE-2021-28966İstismar yok | In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.ruby-lang · ruby · CWE-22 | Yüksek7,5 | — | %57,1 | 30 Tem 2021 |
42Planlayın | CVE-2018-16395İstismar yok | An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3ruby-lang · openssl | Kritik9,8 | — | %10,7 | 16 Kas 2018 |
42Planlayın | CVE-2017-14064İstismar yok | Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.ruby-lang · ruby · CWE-119 | Kritik9,8 | — | %9,4 | 31 Ağu 2017 |
41Planlayın | CVE-2016-2337İstismar yok | Type confusion exists in _cancel_eval Ruby's TclTkIp class method.ruby-lang · ruby | Kritik9,8 | — | %6,2 | 6 Oca 2017 |
41Planlayın | CVE-2017-17790İstismar yok | The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonsruby-lang · ruby · CWE-74 | Kritik9,8 | — | %5,9 | 20 Ara 2017 |
41Planlayın | CVE-2016-2339İstismar yok | An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby.ruby-lang · ruby · CWE-119 | Kritik9,8 | — | %5,2 | 6 Oca 2017 |
41Planlayın | CVE-2008-2663İstismar yok | Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8ruby-lang · ruby · CWE-190 | Kritik10,0 | — | %4,5 | 24 Haz 2008 |
41Planlayın | CVE-2008-2662İstismar yok | Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.ruby-lang · ruby · CWE-189 | Kritik10,0 | — | %4,3 | 24 Haz 2008 |
41Planlayın | CVE-2009-4124İstismar yok | Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to ruby-lang · ruby · CWE-119 | Kritik10,0 | — | %3,9 | 11 Ara 2009 |
41Planlayın | CVE-2013-1948İstismar yok | converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in arob westgeest · md2pdf | Kritik10,0 | — | %2,2 | 25 Nis 2013 |
40Planlayın | CVE-2017-10784İstismar yok | The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers truby-lang · ruby · CWE-287 | Yüksek8,8 | — | %16,4 | 19 Eyl 2017 |
40Planlayın | CVE-2021-41816İstismar yok | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforruby-lang · cgi · CWE-190 | Kritik9,8 | — | %4,8 | 6 Şub 2022 |
40Planlayın | CVE-2016-2338Kavram kanıtı | An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby.ruby-lang · ruby · CWE-787 | Kritik9,8 | — | %4,7 | 28 Eyl 2022 |
40Planlayın | CVE-2016-2336İstismar yok | Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface.ruby-lang · ruby | Kritik9,8 | — | %3,3 | 6 Oca 2017 |
40Planlayın | CVE-2017-9225İstismar yok | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5.php · php · CWE-787 | Kritik9,8 | — | %3,1 | 24 May 2017 |
40Planlayın | CVE-2022-28738İstismar yok | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.ruby-lang · ruby · CWE-415 | Kritik9,8 | — | %2,9 | 9 May 2022 |
40Planlayın | CVE-2011-4121İstismar yok | The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used foruby-lang · ruby · CWE-326 | Kritik9,8 | — | %2,5 | 26 Kas 2019 |
40Planlayın | CVE-2024-27280İstismar yok | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.CWE-120 | Kritik9,8 | — | %2,4 | 14 May 2024 |
40Planlayın | CVE-2017-11465İstismar yok | The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possiruby-lang · ruby · CWE-125 | Kritik9,8 | — | %1,7 | 19 Tem 2017 |
39İzleyin | CVE-2018-8780İstismar yok | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries anruby-lang · ruby · CWE-22 | Kritik9,1 | — | %9,7 | 3 Nis 2018 |
39İzleyin | CVE-2017-0898İstismar yok | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus valruby-lang · ruby · CWE-134 | Kritik9,1 | — | %9,7 | 15 Eyl 2017 |
38İzleyin | CVE-2013-1933İstismar yok | The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows contextdocumentcloud · karteek-docsplit · CWE-78 | Kritik9,3 | — | %1,8 | 25 Nis 2013 |
37İzleyin | CVE-2013-4164Silahlaştırılmış | Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 4ruby-lang · ruby · CWE-119 | Orta6,8 | — | %35,0 | 23 Kas 2013 |
- CVE-2017-1740557Planlayın
Ruby before 2.4.3 allows Net::FTP command injection.
YüksekCVSS 8,8Kavram kanıtıEPSS %74ruby-lang · ruby15 Ara 2017
- CVE-2008-365652Planlayın
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick i
YüksekCVSS 7,8SilahlaştırılmışEPSS %70ruby-lang · ruby12 Ağu 2008
- CVE-2021-2896647Planlayın
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
YüksekCVSS 7,5İstismar yokEPSS %57ruby-lang · ruby30 Tem 2021
- CVE-2018-1639542Planlayın
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3
KritikCVSS 9,8İstismar yokEPSS %11ruby-lang · openssl16 Kas 2018
- CVE-2017-1406442Planlayın
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.
KritikCVSS 9,8İstismar yokEPSS %9ruby-lang · ruby31 Ağu 2017
- CVE-2016-233741Planlayın
Type confusion exists in _cancel_eval Ruby's TclTkIp class method.
KritikCVSS 9,8İstismar yokEPSS %6ruby-lang · ruby6 Oca 2017
- CVE-2017-1779041Planlayın
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demons
KritikCVSS 9,8İstismar yokEPSS %6ruby-lang · ruby20 Ara 2017
- CVE-2016-233941Planlayın
An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby.
KritikCVSS 9,8İstismar yokEPSS %5ruby-lang · ruby6 Oca 2017
- CVE-2008-266341Planlayın
Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8
KritikCVSS 10,0İstismar yokEPSS %4ruby-lang · ruby24 Haz 2008
- CVE-2008-266241Planlayın
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.
KritikCVSS 10,0İstismar yokEPSS %4ruby-lang · ruby24 Haz 2008
- CVE-2009-412441Planlayın
Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to
KritikCVSS 10,0İstismar yokEPSS %4ruby-lang · ruby11 Ara 2009
- CVE-2013-194841Planlayın
converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a
KritikCVSS 10,0İstismar yokEPSS %2rob westgeest · md2pdf25 Nis 2013
- CVE-2017-1078440Planlayın
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers t
YüksekCVSS 8,8İstismar yokEPSS %16ruby-lang · ruby19 Eyl 2017
- CVE-2021-4181640Planlayın
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platfor
KritikCVSS 9,8İstismar yokEPSS %5ruby-lang · cgi6 Şub 2022
- CVE-2016-233840Planlayın
An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby.
KritikCVSS 9,8Kavram kanıtıEPSS %5ruby-lang · ruby28 Eyl 2022
- CVE-2016-233640Planlayın
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface.
KritikCVSS 9,8İstismar yokEPSS %3ruby-lang · ruby6 Oca 2017
- CVE-2017-922540Planlayın
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5.
KritikCVSS 9,8İstismar yokEPSS %3php · php24 May 2017
- CVE-2022-2873840Planlayın
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.
KritikCVSS 9,8İstismar yokEPSS %3ruby-lang · ruby9 May 2022
- CVE-2011-412140Planlayın
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used fo
KritikCVSS 9,8İstismar yokEPSS %3ruby-lang · ruby26 Kas 2019
- CVE-2024-2728040Planlayın
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.
KritikCVSS 9,8İstismar yokEPSS %214 May 2024
- CVE-2017-1146540Planlayın
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possi
KritikCVSS 9,8İstismar yokEPSS %2ruby-lang · ruby19 Tem 2017
- CVE-2018-878039İzleyin
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries an
KritikCVSS 9,1İstismar yokEPSS %10ruby-lang · ruby3 Nis 2018
- CVE-2017-089839İzleyin
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus val
KritikCVSS 9,1İstismar yokEPSS %10ruby-lang · ruby15 Eyl 2017
- CVE-2013-193338İzleyin
The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context
KritikCVSS 9,3İstismar yokEPSS %2documentcloud · karteek-docsplit25 Nis 2013
- CVE-2013-416437İzleyin
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 4
OrtaCVSS 6,8SilahlaştırılmışEPSS %35ruby-lang · ruby23 Kas 2013