Show filters
264 Total Results
Displaying 51-60 of 264
Sort by:
Attacker Value
Unknown

CVE-2022-0080

Disclosure Date: January 02, 2022 (last updated February 23, 2025)
mruby is vulnerable to Heap-based Buffer Overflow
Attacker Value
Unknown

CVE-2021-41819

Disclosure Date: January 01, 2022 (last updated February 23, 2025)
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
Attacker Value
Unknown

CVE-2021-41817

Disclosure Date: January 01, 2022 (last updated February 23, 2025)
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Attacker Value
Unknown

CVE-2021-4188

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
mruby is vulnerable to NULL Pointer Dereference
Attacker Value
Unknown

CVE-2021-4110

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
mruby is vulnerable to NULL Pointer Dereference
Attacker Value
Unknown

CVE-2021-37543

Disclosure Date: August 06, 2021 (last updated November 28, 2024)
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
Attacker Value
Unknown

CVE-2021-28966

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
Attacker Value
Unknown

CVE-2021-31810

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).
Attacker Value
Unknown

CVE-2020-36401

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
Attacker Value
Unknown

CVE-2021-33575

Disclosure Date: May 25, 2021 (last updated November 28, 2024)
The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.