Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2024-7254
Disclosure Date: September 19, 2024 (last updated September 19, 2024)
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
0
Attacker Value
Unknown
CVE-2009-4123
Disclosure Date: December 12, 2023 (last updated December 15, 2023)
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
0
Attacker Value
Unknown
CVE-2012-5370
Disclosure Date: November 28, 2012 (last updated October 05, 2023)
JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.
0
Attacker Value
Unknown
CVE-2010-1330
Disclosure Date: November 23, 2012 (last updated October 05, 2023)
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
0
Attacker Value
Unknown
CVE-2011-4838
Disclosure Date: December 30, 2011 (last updated October 04, 2023)
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
0