Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.9% | — | Ruby-lang RubyRubygemsOracle SolarisRedhat Enterprise Linux | 24/6/2015 | 17/6/2026 | RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack." | |
| Modificada | Media (4.3) | 1.7% | — | RubygemsRuby-lang Ruby | 17/10/2013 | 16/6/2026 | Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via… | |
| Modificada | Media (4.3) | 3.3% | — | Redhat Enterprise LinuxRubygemsRuby-lang Ruby | 17/10/2013 | 16/6/2026 | Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted… | |
| Modificada | Media (4.3) | 1.4% | — | Rubygems | 1/10/2013 | 16/6/2026 | RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack. | |
| Modificada | Media (5.8) | 2.5% | — | Rubygems | 1/10/2013 | 16/6/2026 | RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 3.6% | — | Rubygems Mini Magick | 20/3/2013 | 16/6/2026 | lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Alta (7.5) | 2.3% | — | Rubygems Fastreader | 20/3/2013 | 16/6/2026 | lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Alta (7.5) | 3.6% | — | Rubygems Command Wrap | 20/3/2013 | 16/6/2026 | command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename. | |
| Modificada | Alta (7.5) | 13% | 💥 PoC | Rubygems Json GEM | 13/2/2013 | 16/6/2026 | The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as… | |
| Modificada | Alta (7.5) | 4.5% | — | Rubygems Mail GEM | 18/7/2012 | 16/6/2026 | The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery. | |
| Modificada | Media (5) | 4.9% | — | Rubygems Mail GEM | 18/7/2012 | 16/6/2026 | Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a .. (dot dot) in the to parameter. | |
| Modificada | Alta (9.3) | 4.8% | — | Rubyforge Rubygems | 24/1/2007 | 16/6/2026 | The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages. |