Samuel Giddins
9 exploits
Active since Aug 2017
RubyGems < 2.6.13 - Arbitrary File Write via Specification Name Validation Bypass
CVSS 7.5
RubyGems < 2.2.9, 2.3.6, 2.4.3, 2.5.0 - Directory Traversal via Malicious Gem Installation
CVSS 5.5
RubyGems < 2.6.13 - Terminal Escape Sequence Injection via Gem Specification
CVSS 9.8
RubyGems < 2.6.12 - Denial of Service via Malicious Gem Specification
CVSS 7.5
RubyGems < 2.6.12 - DNS Hijacking via MITM Attack
CVSS 8.1
RubyGems < 2.2.9, 2.3.6, 2.4.3, 2.5.0 - Infinite Loop via Negative Size in Tar Header
CVSS 7.5
RubyGems <2.7.6 - Improper Verification of Cryptographic Signature
CVSS 9.8
RubyGems.org < 2022-08-31 - Account Takeover via Email Change Confirmation Bypass
CVSS 8.3
rubygems.org < 2023-08-14 - Unauthenticated Gem Replacement via Insufficient Input Validation
CVSS 7.4