Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2020-36327

Disclosure Date: April 29, 2021 (last updated November 08, 2023)
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.
Attacker Value
Unknown

CVE-2019-3881

Disclosure Date: September 04, 2020 (last updated February 22, 2025)
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Attacker Value
Unknown

CVE-2017-1000477

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
0
Attacker Value
Unknown

CVE-2016-7954

Disclosure Date: December 22, 2016 (last updated November 25, 2024)
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
0
Attacker Value
Unknown

CVE-2013-0334

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
0
Attacker Value
Unknown

CVE-2014-7328

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The brain abundance info (aka com.wbrainabundance) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2007-4472

Disclosure Date: September 06, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.
0