Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

125 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.29%—Ruby-lang Ruby19331/10/201916/6/2026
ruby193 uses an insecure LD_LIBRARY_PATH setting.
ModificadaMedia (5.5)0.55%—Ruby-lang Webrick10/5/201917/6/2026
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore it is "not a problem.
ModificadaAlta (8.1)8.0%—Ruby-lang RubyCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux16/11/201817/6/2026
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
ModificadaCrítica (9.8)11%—Ruby-lang OpensslRuby-lang RubyCanonical Ubuntu LinuxDebian Linux+116/11/201817/6/2026
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the ordering, non-equal objects may return true. When the first argument is one character longer than…
ModificadaCrítica (9.1)10.0%—Ruby-lang RubyCanonical Ubuntu LinuxDebian Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
ModificadaAlta (7.5)6.9%—Ruby-lang RubyCanonical Ubuntu LinuxDebian Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
ModificadaAlta (7.5)7.5%—Ruby-lang RubyCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.
ModificadaAlta (7.5)4.5%—Ruby-lang RubyDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux3/4/201817/6/2026
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).
ModificadaAlta (7.5)10%—Ruby-lang RubyCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux3/4/201817/6/2026
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
ModificadaMedia (5.3)5.5%—Ruby-lang RubyDebian Linux3/4/201817/6/2026
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.
ModificadaCrítica (9.8)5.9%—Ruby-lang Ruby20/12/201717/6/2026
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.
ModificadaAlta (8.8)74%—Ruby-lang RubyDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+415/12/201717/6/2026
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is…
ModificadaAlta (7.5)7.7%—Ruby-lang Ruby19/9/201717/6/2026
The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.
ModificadaAlta (8.8)16%—Ruby-lang Ruby19/9/201717/6/2026
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.
ModificadaCrítica (9.1)9.7%—Ruby-lang Ruby15/9/201717/6/2026
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.
ModificadaAlta (7.5)4.1%—Ruby-lang Ruby6/9/201717/6/2026
The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.
ModificadaCrítica (9.8)9.4%—Ruby-lang RubyDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+531/8/201717/6/2026
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning a pointer to a string of length zero, which is not the length stored…
ModificadaCrítica (9.8)1.7%—Ruby-lang Ruby19/7/201717/6/2026
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y. NOTE: this might have security relevance as a bypass of a $SAFE…
ModificadaMedia (6.1)3.7%—Ruby-lang Ruby12/6/201717/6/2026
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
ModificadaAlta (7.5)5.1%—Oniguruma Project OnigurumaPHPRuby-lang Ruby24/5/201717/6/2026
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during regular expression compilation. Invalid handling of reg->dmax in forward_search_range() could result in an invalid pointer dereference,…
ModificadaCrítica (9.8)3.1%—Oniguruma Project OnigurumaPHPRuby-lang Ruby24/5/201717/6/2026
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key().…
ModificadaAlta (7.5)3.6%—Ruby-lang Ruby3/4/201717/6/2026
The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted regular expression.
ModificadaAlta (7.3)7.8%—Ruby-lang Ruby29/3/201716/6/2026
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
ModificadaAlta (7.5)3.2%—Ruby-lang OpensslDebian Linux30/1/201717/6/2026
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
ModificadaCrítica (9.8)5.1%—Ruby-lang Ruby6/1/201717/6/2026
An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array…