CVE Browser
Page 1 (more results available)
Vendor: Ruby-Lang Remove filterProduct: Ruby Remove filter Clear allAn issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo i…
ruby: Buffer overread vulnerability in StringIO
ruby: ReDoS vulnerability in Time
ruby/cgi-gem: HTTP response splitting in CGI
ruby: Buffer overrun in String-to-Float conversion
Ruby: Double free in Regexp compilation
ruby: Cookie prefix spoofing in CGI::Cookie.parse
ruby: Regular expression denial of service vulnerability of Date parsing methods
ruby: StartTLS stripping vulnerability in Net::IMAP
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host
ruby: XML round-trip vulnerability in REXML
ruby: Potential HTTP request smuggling in WEBrick
ruby: BasicSocket#read_nonblock method leads to information disclosure
HTTP Response Splitting in Puma
ruby: heap buffer overflow in the Psych::Emitter start_document function
ruby: OpenSSL extension hostname matching implementation violates RFC 6125
ruby: NUL injection vulnerability of File.fnmatch and File.fnmatch?
extension): Insecure way of creation exponent value by private RSA key generation
WEBrick:: HTTPRequest X-Forwarded-* allows arbitrary data
ruby: Code injection via command argument of Shell#test / Shell#[]
ruby: HTTP response splitting in WEBrick
ruby: Regular expression denial of service vulnerability of WEBrick's Digest authentication
ruby: Tainted flags are not propagated in Array#pack and String#unpack with some directives
ruby: OpenSSL::X509:: Name equality check does not work correctly
Showing 1 to 25 CVEs · page 1 (more available)