Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webrick HIGH 7.5
CVE-2009-4492EPSS 16%

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to…

Patch available
Fix from $1,950 2010-01-13
Ruby HIGH 10.0
CVE-2009-4124

Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute a…

Patch available
Fix from $1,950 2009-12-11
Ruby MEDIUM 5.0
CVE-2009-1904EPSS 8%

The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application c…

Patch available
Fix from $1,600 2009-06-11
Ruby MEDIUM 6.8
CVE-2009-0642

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote at…

No fix yet
Fix from $1,600 2009-02-20
Ruby HIGH 7.8
CVE-2008-4310EPSS 14%

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (C…

Mitigation only
Fix from $1,950 2008-12-09
Ruby MEDIUM 5.8
CVE-2008-3905

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and …

Fix: after 1.9
Fix from $1,600 2008-09-04
Ruby MEDIUM 5.0
CVE-2008-3790EPSS 15%

The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (…

Patch available
Fix from $1,600 2008-08-27
Ruby MEDIUM 5.0
CVE-2008-3443EPSS 16%

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows r…

No fix yet
Fix from $1,600 2008-08-14
Ruby HIGH 7.8
CVE-2008-3656EPSS 70%

Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.…

Fix: after 1.8.5
Fix from $1,950 2008-08-13
Ruby HIGH 7.5
CVE-2008-3655EPSS 14%

Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical varia…

Fix: after 1.8.5
Fix from $1,950 2008-08-13
Ruby HIGH 7.5
CVE-2008-3657EPSS 14%

The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inpu…

Fix: after 1.8.5
Fix from $1,950 2008-08-13
Ruby HIGH 7.5
CVE-2008-2376

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2008-07-09
Ruby HIGH 10.0
CVE-2008-2662

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 befor…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby HIGH 10.0
CVE-2008-2663

Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby HIGH 7.8
CVE-2008-2664

The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby HIGH 7.8
CVE-2008-2725

Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby HIGH 7.8
CVE-2008-2726

Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p2…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby MEDIUM 5.0
CVE-2008-1891

Directory traversal vulnerability in WEBrick in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and…

Fix: after 1.9.0
Fix from $1,600 2008-04-18
Webrick MEDIUM 5.0
CVE-2008-1145EPSS 28%

Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that supp…

Patch available
Fix from $1,600 2008-03-04
Ruby MEDIUM 5.0
CVE-2007-5770

The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the common…

Patch available
Fix from $1,600 2007-11-14