Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2016-2338 An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function he… Ruby No fix yet Fix from $2,3002022-09-29 MEDIUM 5.3 CVE-2011-3624 Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser… Ruby Mitigation only Fix from $1,6002019-11-26 MEDIUM 5.5 CVE-2019-11879 The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web … Webrick Mitigation only Fix from $1,6002019-05-10 CRITICAL 9.1 CVE-2017-0898EPSS 10% Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such … Ruby No fix yet Fix from $2,3002017-09-15 HIGH 7.5 CVE-2017-6181 The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attack… Ruby Mitigation only Fix from $1,9502017-04-03 CRITICAL 9.8 CVE-2016-2336 Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than thi… Ruby No fix yet Fix from $2,3002017-01-06 CRITICAL 9.8 CVE-2016-2337EPSS 6% Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cau… Ruby No fix yet Fix from $2,3002017-01-06 CRITICAL 9.8 CVE-2016-2339EPSS 5% An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "i… Ruby No fix yet Fix from $2,3002017-01-06 MEDIUM 5.8 CVE-2014-2734EPSS 5% The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to s… Ruby No fix yet Fix from $1,6002014-04-24 MEDIUM 6.8 CVE-2013-4073 The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.… Ruby Mitigation only Fix from $1,6002013-08-18 MEDIUM 5.0 CVE-2012-4464 Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untai… Ruby Mitigation only Fix from $1,6002013-04-25 MEDIUM 5.0 CVE-2012-4466 Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level… Ruby Mitigation only Fix from $1,6002013-04-25 MEDIUM 5.0 CVE-2012-4522 The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to creat… Ruby Mitigation only Fix from $1,6002012-11-24 MEDIUM 6.7 CVE-2012-5380 Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-level C:\ directory, might allow … Ruby No fix yet Fix from $1,6002012-10-11 MEDIUM 6.8 CVE-2009-0642 ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote at… Ruby No fix yet Fix from $1,6002009-02-20 HIGH 7.8 CVE-2008-4310EPSS 14% httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (C… Ruby Mitigation only Fix from $1,9502008-12-09 MEDIUM 5.0 CVE-2008-3443EPSS 16% The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows r… Ruby No fix yet Fix from $1,6002008-08-14 HIGH 7.5 CVE-2008-2376 Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service… Ruby Mitigation only Fix from $1,9502008-07-09