rubygems

954 tracked vulnerabilities.

CVE-2017-17718 MEDIUM
net-ldap < 0.16.0 - Improper Certificate Validation
Dec 17, 2017
CVSS 5.9
EPSS 0.00
CVE-2017-16355 MEDIUM
Phusion Passenger 5.1.10 - Info Disclosure
Dec 14, 2017
CVSS 4.7
EPSS 0.00
CVE-2017-10906 CRITICAL
Fluentd 0.12.29-0.12.40 - Escape Sequence Injection
Dec 08, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-17042 HIGH
YARD < 0.9.11 - Path Traversal via Relative Path Handling
Nov 28, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-16932 HIGH
libxml2 < 2.9.5 - Denial of Service via Infinite Recursion in Parameter Entities
Nov 23, 2017
CVSS 7.5
EPSS 0.22
CVE-2017-1000248 CRITICAL
Redis-store <=v1.3.0 - Info Disclosure
Nov 17, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-0909 CRITICAL
Private_address_check <0.4.1 - SSRF
Nov 16, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-16833 MEDIUM
gemirro < 0.16.0 - Stored Cross-Site Scripting via Crafted JavaScript URL in Gemspec Homepage
Nov 15, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-0905 CRITICAL
Recurly Client Ruby Library <2.0.13-2.11.3 - SSRF
Nov 13, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-0904 HIGH
Private_address_check <0.4.0 - SSRF
Nov 13, 2017
CVSS 8.1
EPSS 0.01
CVE-2017-0889 CRITICAL
Paperclip 3.1.4-5.1.9 - Server-Side Request Forgery via UriAdapter
Nov 13, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-16792 MEDIUM
geminabox < 0.13.10 - Stored Cross-Site Scripting via Gemspec Homepage Value
Nov 13, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-16516 HIGH
yajl-ruby 1.3.0 - Memory Corruption
Nov 03, 2017
CVSS 7.5
EPSS 0.02
CVE-2017-15928 HIGH
OX < 2.8.1 - Improper Input Validation
Oct 27, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-15364 MEDIUM
Ccsv - Use-After-Free in foreach Function
Oct 15, 2017
CVSS 5.5
EPSS 0.00
CVE-2017-0903 CRITICAL
RubyGems 2.0.0-2.6.13 - Remote Code Execution via YAML Deserialization
Oct 11, 2017
CVSS 9.8
EPSS 0.06
CVE-2017-14683 HIGH
geminabox < 0.13.7 - Cross-Site Request Forgery via Unintended Gem Upload
Sep 25, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-14506 MEDIUM
geminabox < 0.13.6 - Cross-Site Scripting via Crafted Gem Homepage Value
Sep 25, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-14033 HIGH
Ruby < 2.2.8, 2.3.x < 2.3.5, 2.4.x <= 2.4.1 - Denial of Service via OpenSSL::ASN1 Decode Method
Sep 19, 2017
CVSS 7.5
EPSS 0.08
CVE-2017-10784 HIGH
Ruby < 2.2.8, 2.3.x < 2.3.5, 2.4.x <= 2.4.1 - Command Injection via WEBrick Basic Authentication
Sep 19, 2017
CVSS 8.8
EPSS 0.02
CVE-2017-0902 HIGH
RubyGems < 2.6.12 - DNS Hijacking via MITM Attack
Aug 31, 2017
CVSS 8.1
EPSS 0.05
CVE-2017-0901 HIGH
RubyGems < 2.6.13 - Arbitrary File Write via Specification Name Validation Bypass
Aug 31, 2017
CVSS 7.5
EPSS 0.21
CVE-2017-0900 HIGH
RubyGems < 2.6.12 - Denial of Service via Malicious Gem Specification
Aug 31, 2017
CVSS 7.5
EPSS 0.14
CVE-2017-0899 CRITICAL
RubyGems < 2.6.13 - Terminal Escape Sequence Injection via Gem Specification
Aug 31, 2017
CVSS 9.8
EPSS 0.10
CVE-2017-7540 CRITICAL
rubygem-safemode <1.3.2 - Privilege Escalation
Jul 21, 2017
CVSS 9.8
EPSS 0.00