Ruby-Lang / Ruby
93 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-4975 | ruby: off-by-one stack-based buffer overflow in the encodes() function | MEDIUM | 5.0 | Nov 15, 2014 |
| CVE-2014-8080 | ruby: REXML billion laughs attack via parameter entity expansion | MEDIUM | 5.0 | Nov 3, 2014 |
| CVE-2014-2734 | ruby: SSL signature spoofing flaw | MEDIUM | 5.8 | Apr 24, 2014 |
| CVE-2013-4164 | ruby: heap overflow in floating point parsing | MEDIUM | 6.8 | Nov 23, 2013 |
| CVE-2013-2065 | Ruby: Object taint bypassing in DL and Fiddle | MEDIUM | 6.4 | Nov 2, 2013 |
| CVE-2013-4363 | rubygems: version regex algorithmic complexity vulnerability, incomplete CVE-2013-4287 fix | MEDIUM | 4.3 | Oct 17, 2013 |
| CVE-2013-4287 | rubygems: version regex algorithmic complexity vulnerability | MEDIUM | 4.3 | Oct 17, 2013 |
| CVE-2013-4073 | ruby: hostname check bypassing vulnerability in SSL client | MEDIUM | 6.8 | Aug 18, 2013 |
| CVE-2012-4481 | ruby: Incomplete fix for CVE-2011-1005 for NameError#to_s method when used on objects | MEDIUM | 4.3 | May 2, 2013 |
| CVE-2012-4466 | ruby: safe level bypass via name_err_mesg_to_str() | MEDIUM | 5.0 | Apr 25, 2013 |
| CVE-2012-4464 | 1.9.3: Possibility to bypass Ruby's $SAFE (level 4) semantics | MEDIUM | 5.0 | Apr 25, 2013 |
| CVE-2013-1821 | ruby: entity expansion DoS vulnerability in REXML | MEDIUM | 5.0 | Apr 9, 2013 |
| CVE-2013-0256 | rubygem-rdoc: Cross-site scripting in the documentation created by Darkfish Rdoc HTML generator / template | MEDIUM | 5.4 | Mar 1, 2013 |
| CVE-2012-5371 | ruby: Murmur hash-flooding DoS flaw in ruby 1.9 (oCERT-2012-001) | MEDIUM | 5.0 | Nov 28, 2012 |
| CVE-2012-4522 | ruby: unintentional file creation caused by inserting an illegal NUL character | MEDIUM | 5.0 | Nov 24, 2012 |
| CVE-2012-5380 | Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-level C:\ directory, might allow local user… | MEDIUM | 6.7 | Oct 11, 2012 |
| CVE-2011-4815 | ruby: hash table collisions CPU usage DoS (oCERT-2011-003) | HIGH | 7.8 | Dec 30, 2011 |
| CVE-2011-3009 | Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbe… | MEDIUM | 5.0 | Aug 5, 2011 |
| CVE-2011-2705 | The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, wh… | MEDIUM | 5.0 | Aug 5, 2011 |
| CVE-2011-2686 | ruby: Properly initialize the random number generator when forking new process | MEDIUM | 5.0 | Aug 5, 2011 |
| CVE-2011-0188 | ruby: memory corruption in BigDecimal on 64bit platforms | MEDIUM | 6.8 | Mar 23, 2011 |
| CVE-2011-1005 | Ruby: Untrusted codes able to modify arbitrary strings | MEDIUM | 5.0 | Mar 2, 2011 |
| CVE-2011-1004 | Ruby: Symlink race condition by removing directory trees in fileutils module | MEDIUM | 6.3 | Mar 2, 2011 |
| CVE-2010-2489 | Buffer overflow in Ruby 1.9.x before 1.9.1-p429 on Windows might allow local users to gain privileges via a crafted ARGF.inplace_mode value that is not properl… | HIGH | 7.2 | Jul 9, 2010 |
| CVE-2009-4124 | ruby: Heap-based buffer overflow in the rb_str_justify() function | HIGH | 10.0 | Dec 11, 2009 |
Showing 51 to 75 of 93 CVEs