V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

49 / 49
Product: canonical:jruby×Clear all
6.5
CVE-2017-0901DEB
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a malicious…
2017-01-01Pre-auth
EPSS29.4%
pct 97
5.6
CVE-2017-0903DEB
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution v…
2017-01-01Pre-auth
EPSS15.9%
pct 96
4.3
CVE-2017-0899DEB
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications tha…
2017-01-01Pre-auth
EPSS10.8%
pct 95
7.9
CVE-2015-3900DEB
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the …
2015-01-01
EPSS8.9%
pct 94
4.3
CVE-2017-0900DEB
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to …
2017-01-01Pre-auth
EPSS8.5%
pct 94
4.7
CVE-2017-17742AST
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-previ…
2017-01-01Pre-auth
EPSS5.8%
pct 92
7.5
CVE-2019-16201AST
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6…
2019-01-01Pre-auth
EPSS5.1%
pct 91
5.5
CVE-2018-1000073AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01
EPSS5.1%
pct 91
3.3
CVE-2018-1000075AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01
EPSS4.8%
pct 90
7.5
CVE-2017-0902DEB
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows …
2017-01-01Pre-auth
EPSS4.8%
pct 90
5.3
CVE-2019-16254AST
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting…
2019-01-01Pre-auth
EPSS4.6%
pct 90
5.0
CVE-2011-4838DEB
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash colli…
2011-01-01
EPSS4.4%
pct 89
8.1
CVE-2019-16255AST
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the f…
2019-01-01Pre-auth
EPSS4.2%
pct 89
7.4
CVE-2019-8320AST
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before ma…
2019-01-01Pre-auth
EPSS4.2%
pct 89
5.5
CVE-2018-1000077AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01
EPSS3.8%
pct 88
7.9
CVE-2015-4020DEB
RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the …
2015-01-01
EPSS3.5%
pct 87
5.3
CVE-2019-8325AST
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run …
2019-01-01Pre-auth
EPSS3.4%
pct 87
5.3
CVE-2019-8323AST
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_r…
2019-01-01Pre-auth
EPSS3.4%
pct 87
5.3
CVE-2019-8322AST
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs …
2019-01-01Pre-auth
EPSS3.4%
pct 87
5.3
CVE-2019-8321AST
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#ver…
2019-01-01Pre-auth
EPSS3.4%
pct 87
6.5
CVE-2019-15845AST
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking withi…
2019-01-01Pre-auth
EPSS3.3%
pct 86
7.2
CVE-2019-8324AST
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-lin…
2019-01-01
EPSS3.2%
pct 86
5.5
CVE-2018-1000076AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01
EPSS3.0%
pct 85
7.8
CVE-2018-1000074AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01
EPSS3.0%
pct 85
5.5
CVE-2018-1000079AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01
EPSS2.9%
pct 84
6.1
CVE-2018-1000078AST
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2…
2018-01-01Pre-auth
EPSS2.8%
pct 84
5.3
CVE-2023-28755AST
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI…
2023-01-01Pre-auth
EPSS2.6%
pct 83
4.0
CVE-2012-2125DEB
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote…
2012-01-01
EPSS2.5%
pct 82
5.3
CVE-2023-28756AST
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Tim…
2023-01-01Pre-auth
EPSS2.5%
pct 82
8.8
CVE-2021-33621AST
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP res…
2021-01-01
EPSS2.3%
pct 80
5.0
CVE-2012-5370DEB
JRuby computes hash values without properly restricting the ability to trigger hash collisions …
2012-01-01
EPSS2.2%
pct 80
5.3
CVE-2024-35176ANC
REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerabi…
2024-01-01Pre-auth
EPSS2.1%
pct 78
4.5
CVE-2024-27281ANC
An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. …
2024-01-01
EPSS1.6%
pct 72
5.3
CVE-2023-36617AST
A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishan…
2023-01-01Pre-auth
EPSS1.5%
pct 71
6.6
CVE-2024-49761ANC
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it …
2024-01-01Pre-auth
EPSS1.4%
pct 69
4.3
CVE-2024-39908ANC
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when…
2024-01-01Pre-auth
EPSS1.4%
pct 68
4.0
CVE-2012-2126DEB
RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to mod…
2012-01-01
EPSS1.4%
pct 68
5.3
CVE-2024-41123ANC
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when …
2024-01-01Pre-auth
EPSS1.3%
pct 66
3.3
CVE-2024-41946ANC
REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an…
2024-01-01
EPSS1.2%
pct 63
7.5
CVE-2025-27219ANC
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains …
2025-01-01Pre-auth
EPSS0.8%
pct 51
Select a vulnerability on the left to open the preview.