Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2020-36327
Disclosure Date: April 29, 2021 (last updated November 08, 2023)
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
0
Attacker Value
Unknown
CVE-2019-3881
Disclosure Date: September 04, 2020 (last updated February 22, 2025)
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
0
Attacker Value
Unknown
CVE-2017-1000477
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
0
Attacker Value
Unknown
CVE-2016-7954
Disclosure Date: December 22, 2016 (last updated November 25, 2024)
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
0
Attacker Value
Unknown
CVE-2013-0334
Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
0
Attacker Value
Unknown
CVE-2014-7328
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The brain abundance info (aka com.wbrainabundance) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2007-4472
Disclosure Date: September 06, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.
0