Vulnerabilities > Ruby Lang

DATE CVE VULNERABILITY TITLE RISK
2022-05-09 CVE-2022-28738 Double Free vulnerability in Ruby-Lang Ruby
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2.
network
low complexity
ruby-lang CWE-415
7.5
2022-05-09 CVE-2022-28739 Out-of-bounds Read vulnerability in multiple products
There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2.
4.3
2022-02-06 CVE-2021-41816 Integer Overflow or Wraparound vulnerability in Ruby-Lang CGI
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes.
network
low complexity
ruby-lang CWE-190
7.5
2022-01-01 CVE-2021-41819 Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names.
5.0
2022-01-01 CVE-2021-41817 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. 5.0
2021-08-01 CVE-2021-32066 Inadequate Encryption Strength vulnerability in multiple products
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1.
5.8
2021-07-30 CVE-2021-28966 Path Traversal vulnerability in Ruby-Lang Ruby
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
network
low complexity
ruby-lang CWE-22
5.0
2021-07-30 CVE-2021-31799 Command Injection vulnerability in multiple products
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
4.4
2021-07-13 CVE-2021-31810 Exposure of Resource to Wrong Sphere vulnerability in multiple products
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1.
network
low complexity
ruby-lang debian oracle CWE-668
5.0
2021-04-21 CVE-2021-28965 XXE vulnerability in multiple products
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues.
network
low complexity
ruby-lang fedoraproject CWE-611
5.0