Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-7254

Disclosure Date: September 19, 2024 (last updated September 19, 2024)
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
0
Attacker Value
Unknown

CVE-2009-4123

Disclosure Date: December 12, 2023 (last updated December 15, 2023)
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
Attacker Value
Unknown

CVE-2012-5370

Disclosure Date: November 28, 2012 (last updated October 05, 2023)
JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.
0
Attacker Value
Unknown

CVE-2010-1330

Disclosure Date: November 23, 2012 (last updated October 05, 2023)
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
0
Attacker Value
Unknown

CVE-2011-4838

Disclosure Date: December 30, 2011 (last updated October 04, 2023)
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
0