Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-41817 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1… Date 2.0.1 / 2.6.9+ Fix from $1,9502022-01-01 HIGH 7.4 CVE-2021-32066 An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an exception when StartTLS fails … Ruby 9.2.6.1+ Fix from $1,9502021-08-01 HIGH 7.5 CVE-2021-28966EPSS 57% In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir. Ruby 2.7.3 / 3.0.1+ Fix from $1,9502021-07-30 MEDIUM 5.8 CVE-2021-31810 An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick … Ruby 9.2.6.1+ Fix from $1,6002021-07-13 HIGH 7.5 CVE-2021-28965EPSS 5% The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorre… Rexml 2.6.7 / 2.7.3+ Fix from $1,9502021-04-21 HIGH 7.5 CVE-2020-25613 An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not… Ruby after 2.7.1 Fix from $1,9502020-10-06 MEDIUM 5.3 CVE-2020-10933 An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buff… Ruby after 2.6.5 Fix from $1,6002020-05-04 MEDIUM 5.9 CVE-2015-1855 verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properl… Ruby 2.1.6 / 2.2.2+ Fix from $1,6002019-11-29 HIGH 8.1 CVE-2019-16255 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[]… Ruby after 2.6.4 Fix from $1,9502019-11-26 HIGH 7.5 CVE-2019-16201EPSS 5% WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by… Ruby after 2.6.4 Fix from $1,9502019-11-26 MEDIUM 5.3 CVE-2019-16254 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input i… Ruby after 2.6.4 Fix from $1,6002019-11-26 MEDIUM 6.5 CVE-2019-15845 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions. Ruby after 2.6.4 Fix from $1,6002019-11-26 CRITICAL 9.8 CVE-2011-4121 The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private… Ruby 1.9.3+ Fix from $2,3002019-11-26 MEDIUM 5.3 CVE-2011-3624 Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser… Ruby Mitigation only Fix from $1,6002019-11-26 MEDIUM 5.5 CVE-2019-11879 The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web … Webrick Mitigation only Fix from $1,6002019-05-10 HIGH 8.1 CVE-2018-16396EPSS 8% An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that… Ruby after 2.5.1 Fix from $1,9502018-11-16 CRITICAL 9.8 CVE-2018-16395EPSS 11% An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When tw… OpenSSL 2.1.2+ Fix from $2,3002018-11-16 CRITICAL 9.1 CVE-2018-8780EPSS 10% In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.emp… Ruby 2.2.10 / 2.3.7+ Fix from $2,3002018-04-03 HIGH 7.5 CVE-2018-6914EPSS 10% Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5… Ruby 2.2.10 / 2.3.7+ Fix from $1,9502018-04-03 HIGH 7.5 CVE-2018-8777 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with… Ruby 2.2.10 / 2.3.7+ Fix from $1,9502018-04-03 HIGH 7.5 CVE-2018-8778EPSS 8% In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (… Ruby 2.2.10 / 2.3.7+ Fix from $1,9502018-04-03 HIGH 7.5 CVE-2018-8779EPSS 7% In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open method… Ruby 2.2.10 / 2.3.7+ Fix from $1,9502018-04-03 MEDIUM 5.3 CVE-2017-17742EPSS 6% Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attac… Ruby 2.2.10 / 2.3.7+ Fix from $1,6002018-04-03 CRITICAL 9.8 CVE-2017-17790EPSS 6% The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by… Ruby after 2.4.2 Fix from $2,3002017-12-20 HIGH 8.8 CVE-2017-17405EPSS 74% Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to… Ruby after 2.4.2 Fix from $1,9502017-12-15 HIGH 8.8 CVE-2017-10784EPSS 16% The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject … Ruby after 2.2.7 Fix from $1,9502017-09-19 HIGH 7.5 CVE-2017-14033EPSS 8% The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of… Ruby Patch available Fix from $1,9502017-09-19 CRITICAL 9.1 CVE-2017-0898EPSS 10% Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such … Ruby No fix yet Fix from $2,3002017-09-15 HIGH 7.5 CVE-2014-6438 The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular express… Ruby after 1.9.2 Fix from $1,9502017-09-06 CRITICAL 9.8 CVE-2017-14064EPSS 9% Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using st… Ruby after 2.2.7 Fix from $2,3002017-08-31