Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ruby CRITICAL 9.8
CVE-2016-2338

An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function he…

No fix yet
Fix from $2,300 2022-09-29
Ruby MEDIUM 5.3
CVE-2011-3624

Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Ser…

Mitigation only
Fix from $1,600 2019-11-26
Webrick MEDIUM 5.5
CVE-2019-11879

The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web …

Mitigation only
Fix from $1,600 2019-05-10
Ruby CRITICAL 9.1
CVE-2017-0898EPSS 10%

Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such …

No fix yet
Fix from $2,300 2017-09-15
Ruby HIGH 7.5
CVE-2017-6181

The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attack…

Mitigation only
Fix from $1,950 2017-04-03
Ruby CRITICAL 9.8
CVE-2016-2336

Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than thi…

No fix yet
Fix from $2,300 2017-01-06
Ruby CRITICAL 9.8
CVE-2016-2337EPSS 6%

Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cau…

No fix yet
Fix from $2,300 2017-01-06
Ruby CRITICAL 9.8
CVE-2016-2339EPSS 5%

An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "i…

No fix yet
Fix from $2,300 2017-01-06
Ruby MEDIUM 5.8
CVE-2014-2734EPSS 5%

The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to s…

No fix yet
Fix from $1,600 2014-04-24
Ruby MEDIUM 6.8
CVE-2013-4073

The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.…

Mitigation only
Fix from $1,600 2013-08-18
Ruby MEDIUM 5.0
CVE-2012-4464

Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untai…

Mitigation only
Fix from $1,600 2013-04-25
Ruby MEDIUM 5.0
CVE-2012-4466

Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level…

Mitigation only
Fix from $1,600 2013-04-25
Ruby MEDIUM 5.0
CVE-2012-4522

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to creat…

Mitigation only
Fix from $1,600 2012-11-24
Ruby MEDIUM 6.7
CVE-2012-5380

Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-level C:\ directory, might allow …

No fix yet
Fix from $1,600 2012-10-11
Ruby MEDIUM 6.8
CVE-2009-0642

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote at…

No fix yet
Fix from $1,600 2009-02-20
Ruby HIGH 7.8
CVE-2008-4310EPSS 14%

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (C…

Mitigation only
Fix from $1,950 2008-12-09
Ruby MEDIUM 5.0
CVE-2008-3443EPSS 16%

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows r…

No fix yet
Fix from $1,600 2008-08-14
Ruby HIGH 7.5
CVE-2008-2376

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2008-07-09