CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames
resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
Net::IMAP: Command Injection via ID command argument
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Net::IMAP: Denial of Service via incomplete raw argument validation
net-imap: Command Injection via unvalidated Symbol inputs
net-imap: Command Injection via "raw" arguments to multiple commands
net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
net-imap: Quadratic complexity when reading response literals
net-imap vulnerable to STARTTLS stripping via invalid response timing
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Ruby JSON has a format string injection vulnerability
URI Credential Leakage Bypass over CVE-2025-27221
REXML has a DoS condition when parsing malformed XML file
resolv: Denial of Service in resolv gem
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Ruby JSON Parser has Out-of-bounds Read
Net::IMAP vulnerable to possible DoS by memory exhaustion
REXML ReDoS vulnerability
REXML denial of service vulnerability
REXML DoS vulnerability
Showing 1 to 25 CVEs · page 1 (more available)