VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Ruby Lang
>
Ruby
> 2.7.2
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2023-03-31
CVE-2023-28756
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1.
network
low complexity
ruby-lang
debian
fedoraproject
5.3
5.3
2022-11-18
CVE-2021-33621
Injection vulnerability in multiple products
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting.
network
low complexity
ruby-lang
fedoraproject
CWE-74
8.8
8.8
2022-05-09
CVE-2022-28739
Out-of-bounds Read vulnerability in multiple products
There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2.
network
low complexity
ruby-lang
debian
apple
CWE-125
7.5
7.5
2022-01-01
CVE-2021-41819
Reliance on Cookies without Validation and Integrity Checking vulnerability in multiple products
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names.
network
low complexity
ruby-lang
redhat
debian
suse
opensuse
fedoraproject
CWE-565
7.5
7.5
2022-01-01
CVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string.
network
low complexity
ruby-lang
redhat
fedoraproject
debian
suse
opensuse
7.5
7.5
2021-08-01
CVE-2021-32066
Improper Handling of Exceptional Conditions vulnerability in multiple products
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1.
network
high complexity
ruby-lang
oracle
CWE-755
7.4
7.4
2021-07-30
CVE-2021-28966
Path Traversal vulnerability in Ruby-Lang Ruby
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
network
low complexity
ruby-lang
CWE-22
7.5
7.5
2021-07-13
CVE-2021-31810
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1.
network
low complexity
ruby-lang
debian
oracle
5.8
5.8
2021-04-21
CVE-2021-28965
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues.
network
low complexity
ruby-lang
fedoraproject
7.5
7.5