CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo i…
net-imap: Command Injection via unvalidated Symbol inputs
net-imap: Command Injection via "raw" arguments to multiple commands
net-imap: Denial of service via high iteration count for `SCRAM-*` authentication
net-imap: Quadratic complexity when reading response literals
net-imap vulnerable to STARTTLS stripping via invalid response timing
zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
Ruby JSON has a format string injection vulnerability
URI Credential Leakage Bypass over CVE-2025-27221
REXML has a DoS condition when parsing malformed XML file
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Ruby JSON Parser has Out-of-bounds Read
uri: userinfo leakage in URI#join, URI#merge and URI#+
CGI: ReDoS in CGI::Util#escapeElement
CGI: Denial of Service in CGI::Cookie.parse
REXML ReDoS vulnerability
REXML denial of service vulnerability
REXML DoS vulnerability
REXML DoS vulnerability
Denial of service in REXML
REXML contains a denial of service vulnerability
ruby: Buffer overread vulnerability in StringIO
rubygem-uri: ReDoS vulnerability - upstream's incomplete fix for CVE-2023-28755
ruby: ReDoS vulnerability in Time
Showing 1 to 25 CVEs · page 1 (more available)