Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Date HIGH 7.5
CVE-2021-41817

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1…

Fix: 2.0.1 / 2.6.9+
Fix from $1,950 2022-01-01
Ruby HIGH 7.4
CVE-2021-32066

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails …

Fix: 9.2.6.1+
Fix from $1,950 2021-08-01
Ruby HIGH 7.5
CVE-2021-28966EPSS 57%

In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.

Fix: 2.7.3 / 3.0.1+
Fix from $1,950 2021-07-30
Ruby MEDIUM 5.8
CVE-2021-31810

An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick …

Fix: 9.2.6.1+
Fix from $1,600 2021-07-13
Rexml HIGH 7.5
CVE-2021-28965EPSS 5%

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorre…

Fix: 2.6.7 / 2.7.3+
Fix from $1,950 2021-04-21
Ruby HIGH 7.5
CVE-2020-25613

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not…

Fix: after 2.7.1
Fix from $1,950 2020-10-06
Ruby MEDIUM 5.3
CVE-2020-10933

An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buff…

Fix: after 2.6.5
Fix from $1,600 2020-05-04
Ruby MEDIUM 5.9
CVE-2015-1855

verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properl…

Fix: 2.1.6 / 2.2.2+
Fix from $1,600 2019-11-29
Ruby HIGH 8.1
CVE-2019-16255

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[]…

Fix: after 2.6.4
Fix from $1,950 2019-11-26
Ruby HIGH 7.5
CVE-2019-16201EPSS 5%

WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by…

Fix: after 2.6.4
Fix from $1,950 2019-11-26
Ruby MEDIUM 5.3
CVE-2019-16254

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input i…

Fix: after 2.6.4
Fix from $1,600 2019-11-26
Ruby MEDIUM 6.5
CVE-2019-15845

Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.

Fix: after 2.6.4
Fix from $1,600 2019-11-26
Ruby CRITICAL 9.8
CVE-2011-4121

The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private…

Fix: 1.9.3+
Fix from $2,300 2019-11-26
Ruby MEDIUM 5.3
CVE-2011-3624

Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser…

Mitigation only
Fix from $1,600 2019-11-26
Webrick MEDIUM 5.5
CVE-2019-11879

The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web …

Mitigation only
Fix from $1,600 2019-05-10
Ruby HIGH 8.1
CVE-2018-16396EPSS 8%

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that…

Fix: after 2.5.1
Fix from $1,950 2018-11-16
OpenSSL CRITICAL 9.8
CVE-2018-16395EPSS 11%

An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When tw…

Fix: 2.1.2+
Fix from $2,300 2018-11-16
Ruby CRITICAL 9.1
CVE-2018-8780EPSS 10%

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.emp…

Fix: 2.2.10 / 2.3.7+
Fix from $2,300 2018-04-03
Ruby HIGH 7.5
CVE-2018-6914EPSS 10%

Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5…

Fix: 2.2.10 / 2.3.7+
Fix from $1,950 2018-04-03
Ruby HIGH 7.5
CVE-2018-8777

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with…

Fix: 2.2.10 / 2.3.7+
Fix from $1,950 2018-04-03
Ruby HIGH 7.5
CVE-2018-8778EPSS 8%

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (…

Fix: 2.2.10 / 2.3.7+
Fix from $1,950 2018-04-03
Ruby HIGH 7.5
CVE-2018-8779EPSS 7%

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open method…

Fix: 2.2.10 / 2.3.7+
Fix from $1,950 2018-04-03
Ruby MEDIUM 5.3
CVE-2017-17742EPSS 6%

Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attac…

Fix: 2.2.10 / 2.3.7+
Fix from $1,600 2018-04-03
Ruby CRITICAL 9.8
CVE-2017-17790EPSS 6%

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by…

Fix: after 2.4.2
Fix from $2,300 2017-12-20
Ruby HIGH 8.8
CVE-2017-17405EPSS 74%

Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to…

Fix: after 2.4.2
Fix from $1,950 2017-12-15
Ruby HIGH 8.8
CVE-2017-10784EPSS 16%

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject …

Fix: after 2.2.7
Fix from $1,950 2017-09-19
Ruby HIGH 7.5
CVE-2017-14033EPSS 8%

The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of…

Patch available
Fix from $1,950 2017-09-19
Ruby CRITICAL 9.1
CVE-2017-0898EPSS 10%

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such …

No fix yet
Fix from $2,300 2017-09-15
Ruby HIGH 7.5
CVE-2014-6438

The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular express…

Fix: after 1.9.2
Fix from $1,950 2017-09-06
Ruby CRITICAL 9.8
CVE-2017-14064EPSS 9%

Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using st…

Fix: after 2.2.7
Fix from $2,300 2017-08-31