Show filters
264 Total Results
Displaying 51-60 of 264
Sort by:
Attacker Value
Unknown
CVE-2022-0080
Disclosure Date: January 02, 2022 (last updated February 23, 2025)
mruby is vulnerable to Heap-based Buffer Overflow
0
Attacker Value
Unknown
CVE-2021-41819
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
0
Attacker Value
Unknown
CVE-2021-41817
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
0
Attacker Value
Unknown
CVE-2021-4188
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
mruby is vulnerable to NULL Pointer Dereference
0
Attacker Value
Unknown
CVE-2021-4110
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
mruby is vulnerable to NULL Pointer Dereference
0
Attacker Value
Unknown
CVE-2021-37543
Disclosure Date: August 06, 2021 (last updated November 28, 2024)
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
0
Attacker Value
Unknown
CVE-2021-28966
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
0
Attacker Value
Unknown
CVE-2021-31810
Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).
0
Attacker Value
Unknown
CVE-2020-36401
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
0
Attacker Value
Unknown
CVE-2021-33575
Disclosure Date: May 25, 2021 (last updated November 28, 2024)
The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.
0