Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 215 respecto a la semana anterior
Críticas / altas1356▲ 25 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 14% | — | Ruby-lang Ruby | 13/8/2008 | 16/6/2026 | Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3)… | |
| Modificada | Alta (7.5) | 14% | — | Ruby-lang Ruby | 13/8/2008 | 16/6/2026 | The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen. | |
| Modificada | Alta (7.5) | 3.6% | — | Ruby-lang Ruby | 9/7/2008 | 16/6/2026 | Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE. NOTE: this issue exists… | |
| Modificada | Alta (10) | 4.3% | — | Ruby-lang RubyDebian LinuxCanonical Ubuntu Linux | 24/6/2008 | 16/6/2026 | Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors that trigger memory… | |
| Modificada | Alta (7.8) | 3.7% | — | Ruby-lang RubyDebian LinuxCanonical Ubuntu Linux | 24/6/2008 | 16/6/2026 | Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the "REALLOC_N" variant,… | |
| Modificada | Alta (10) | 4.5% | — | Ruby-lang RubyDebian LinuxCanonical Ubuntu Linux | 24/6/2008 | 16/6/2026 | Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662,… | |
| Modificada | Alta (7.8) | 3.8% | — | Ruby-lang RubyDebian LinuxCanonical Ubuntu Linux | 24/6/2008 | 16/6/2026 | Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.… | |
| Modificada | Alta (7.8) | 4.3% | — | Ruby-lang RubyDebian LinuxCanonical Ubuntu Linux | 24/6/2008 | 16/6/2026 | The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and… | |
| Modificada | Media (5) | 2.8% | — | Ruby-lang Ruby | 18/4/2008 | 16/6/2026 | Directory traversal vulnerability in WEBrick in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2, when using NTFS or FAT filesystems, allows remote attackers to read arbitrary CGI files via a trailing (1) + (plus), (2) %2b (encoded plus), (3) .… | |
| Modificada | Media (5) | 28% | — | Ruby-lang WebrickFedoraproject Fedora | 4/3/2008 | 16/6/2026 | Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2)… | |
| Modificada | Media (6.8) | 3.4% | — | Ruby Gnome2 | 30/11/2007 | 16/6/2026 | Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows context-dependent attackers to execute arbitrary code via format string specifiers in the message parameter. | |
| Modificada | Media (6.8) | 2.5% | — | Rubyonrails Rails | 21/11/2007 | 16/6/2026 | The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct… | |
| Modificada | Media (5) | 1.9% | — | Ruby-lang Ruby | 14/11/2007 | 16/6/2026 | The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via… | |
| Modificada | Media (6.8) | 3.6% | — | David Hansson Ruby ON Rails | 19/10/2007 | 16/6/2026 | Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web sessions via unspecified vectors related to "URL-based sessions." | |
| Modificada | Media (5) | 4.0% | — | David Hansson Ruby ON Rails | 19/10/2007 | 16/6/2026 | Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin… | |
| Modificada | Media (4.3) | 1.7% | — | Ruby-lang Ruby | 1/10/2007 | 16/6/2026 | The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a… | |
| Modificada | Media (4.3) | 3.7% | — | Rubyonrails Rails | 14/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values. | |
| Modificada | Alta (9.3) | 4.8% | — | Rubyforge Rubygems | 24/1/2007 | 16/6/2026 | The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages. | |
| Modificada | Media (5) | 3.8% | — | Yukihiro Matsumoto Ruby | 6/12/2006 | 16/6/2026 | The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than CVE-2006-5467. | |
| Modificada | Media (5) | 4.5% | — | Yukihiro Matsumoto Ruby | 27/10/2006 | 16/6/2026 | The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-" instead of "--" and contains an inconsistent… | |
| Modificada | Alta (7.5) | 3.1% | — | Rubyonrails Rails | 14/8/2006 | 16/6/2026 | Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than… | |
| Modificada | Alta (7.5) | 2.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 14/8/2006 | 16/6/2026 | Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112. | |
| Modificada | Media (6.4) | 5.8% | — | Yukihiro Matsumoto Ruby | 21/7/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations". | |
| Modificada | Media (5) | 10% | — | Yukihiro Matsumoto Ruby | 20/4/2006 | 16/6/2026 | The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data. | |
| Modificada | Alta (7.5) | 3.3% | — | Yukihiro Matsumoto Ruby | 7/10/2005 | 16/6/2026 | Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin). |