Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Bibtex-ruby Project Bibtex-ruby | 22/1/2020 | 17/6/2026 | BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mruby | 11/1/2020 | 17/6/2026 | In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mruby | 11/1/2020 | 17/6/2026 | In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mruby | 11/1/2020 | 17/6/2026 | In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c. | |
| Modificada | Media (5.9) | 2.8% | — | Ruby-lang RubyRuby-lang TrunkDebian LinuxPuppet Agent+1 | 29/11/2019 | 17/6/2026 | verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and… | |
| Modificada | Alta (8.1) | 4.2% | — | Ruby-lang RubyDebian LinuxOpensuse LeapOracle Graalvm | 26/11/2019 | 17/6/2026 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method. | |
| Modificada | Media (5.3) | 4.6% | — | Ruby-lang RubyDebian Linux | 26/11/2019 | 17/6/2026 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. NOTE: this issue… | |
| Modificada | Alta (7.5) | 5.1% | — | Ruby-lang RubyDebian Linux | 26/11/2019 | 17/6/2026 | WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses DigestAuth to the Internet or a untrusted network. | |
| Modificada | Media (6.5) | 3.3% | — | Ruby-lang RubyCanonical Ubuntu Linux | 26/11/2019 | 17/6/2026 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions. | |
| Modificada | Crítica (9.8) | 2.5% | — | Ruby-lang Ruby | 26/11/2019 | 16/6/2026 | The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism. | |
| Modificada | Media (5.3) | 1.5% | — | Ruby-lang Ruby | 26/11/2019 | 16/6/2026 | Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header. | |
| Modificada | Crítica (9.8) | 2.7% | — | Distributed Ruby Project Distributed Ruby | 18/11/2019 | 16/6/2026 | Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval. | |
| Modificada | Crítica (9.8) | 2.1% | — | Distributed Ruby Project Distributed Ruby | 18/11/2019 | 16/6/2026 | Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls. | |
| Modificada | Media (6.5) | 1.1% | — | Rubyonrails RailsDebian Linux | 12/11/2019 | 16/6/2026 | The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. | |
| Modificada | Crítica (9.8) | 3.4% | — | Ruby-rbot Rbot | 6/11/2019 | 16/6/2026 | Rbot Reaction plugin allows command execution | |
| Modificada | Baja (3.3) | 0.29% | — | Ruby-lang Ruby193 | 31/10/2019 | 16/6/2026 | ruby193 uses an insecure LD_LIBRARY_PATH setting. | |
| Modificada | Alta (7.8) | 0.33% | — | Zenspider Ruby Parser-legacy | 24/10/2019 | 17/6/2026 | The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert malicious code into the… | |
| Modificada | Media (5.5) | 1.6% | — | Rubyzip Project RubyzipFedoraproject FedoraRedhat Cloudforms | 25/9/2019 | 17/6/2026 | In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). | |
| Modificada | Crítica (9.8) | 1.4% | — | Airbrake Ruby | 6/9/2019 | 17/6/2026 | The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected). | |
| Modificada | Alta (7.4) | 0.64% | — | Elastic Apm-agent-ruby | 30/7/2019 | 17/6/2026 | A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack… | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsDebian LinuxOpensuse Leap | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur. | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsDebian LinuxOpensuse Leap | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur. | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsDebian LinuxOpensuse Leap | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible. | |
| Modificada | Alta (7.5) | 3.3% | — | RubygemsOpensuse LeapDebian Linux | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.) | |
| Modificada | Alta (8.8) | 3.2% | — | RubygemsDebian LinuxOpensuse LeapRedhat Enterprise Linux | 17/6/2019 | 17/6/2026 | An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check. |