Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 10% | — | Ruby-lang RubyCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux | 3/4/2018 | 17/6/2026 | Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument. | |
| Modificada | Media (5.3) | 5.5% | — | Ruby-lang RubyDebian Linux | 3/4/2018 | 17/6/2026 | Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick. | |
| Modificada | Media (6.1) | 1.3% | — | Rubyonrails Html Sanitizer | 30/3/2018 | 17/6/2026 | There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar… | |
| Modificada | Media (5.5) | 2.8% | — | Rubygems | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem… | |
| Modificada | Media (6.1) | 2.7% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability in gem server display of homepage attribute that can result in XSS. This… | |
| Modificada | Media (5.3) | 3.6% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Input Validation vulnerability in ruby gems specification homepage attribute that can result in a malicious… | |
| Modificada | Crítica (9.8) | 2.9% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature vulnerability in package.rb that can result in a mis-signed gem… | |
| Modificada | Alta (7.5) | 4.7% | — | RubygemsDebian Linux | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar header that can result in a negative size… | |
| Modificada | Alta (7.8) | 2.9% | — | Rubygems | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack… | |
| Modificada | Alta (7.5) | 4.9% | — | Rubygems | 13/3/2018 | 17/6/2026 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in install_location function of package.rb that can result in path traversal when… | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Ruby ON Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Ruby ON Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 2.3% | — | Rubyonrails Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Alta (8.1) | 1.5% | — | Rubyonrails Rails | 29/12/2017 | 17/6/2026 | SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input | |
| Modificada | Crítica (9.8) | 5.9% | — | Ruby-lang Ruby | 20/12/2017 | 17/6/2026 | The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely. | |
| Modificada | Alta (8.8) | 74% | — | Ruby-lang RubyDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 15/12/2017 | 17/6/2026 | Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is… | |
| Modificada | Crítica (9.8) | 2.6% | — | Recurly Client Ruby | 13/11/2017 | 17/6/2026 | The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of API keys or other critical resources. | |
| Modificada | Alta (7.5) | 3.8% | — | Yajl-ruby Project Yajl-rubyDebian Linux | 3/11/2017 | 17/6/2026 | In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service. | |
| Modificada | Crítica (9.8) | 16% | — | RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 11/10/2017 | 17/6/2026 | RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. | |
| Modificada | Alta (7.5) | 7.7% | — | Ruby-lang Ruby | 19/9/2017 | 17/6/2026 | The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string. | |
| Modificada | Alta (8.8) | 16% | — | Ruby-lang Ruby | 19/9/2017 | 17/6/2026 | The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name. | |
| Modificada | Crítica (9.1) | 9.7% | — | Ruby-lang Ruby | 15/9/2017 | 17/6/2026 | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap. | |
| Modificada | Alta (7.5) | 4.1% | — | Ruby-lang Ruby | 6/9/2017 | 17/6/2026 | The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string. | |
| Modificada | Alta (8.1) | 4.7% | — | RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls. | |
| Modificada | Alta (7.5) | 29% | — | RubygemsDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem. |