Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ruby MEDIUM 5.0
CVE-2006-6303

The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote atta…

Patch available
Fix from $1,600 2006-12-06
Ruby MEDIUM 5.0
CVE-2006-5467

The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with…

Patch available
Fix from $1,600 2006-10-27
Ruby MEDIUM 6.4
CVE-2006-3694EPSS 6%

Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) …

Patch available
Fix from $1,600 2006-07-21
Ruby MEDIUM 5.0
CVE-2006-1931EPSS 10%

The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a la…

Patch available
Fix from $1,600 2006-04-20
Ruby HIGH 7.5
CVE-2005-2337

Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections an…

Patch available
Fix from $1,950 2005-10-07
Ruby HIGH 7.5
CVE-2005-1992EPSS 7%

The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, wh…

Patch available
Fix from $1,950 2005-06-20
Ruby MEDIUM 5.0
CVE-2004-0983

The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumptio…

Patch available
Fix from $1,600 2005-03-01