Vulnerabilities

Summary — last 7 days

New vulnerabilities2,829▼ 255 vs. last week
Critical / high1,324▼ 180 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.5)1.1%—Yajl Project YajlFedoraproject FedoraDebian Linux6/6/20236/17/2026
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
ModifiedHigh (7.5)3.5%—Yajl-ruby Project Yajl-ruby4/5/20226/17/2026
yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer…
ModifiedHigh (7.5)3.8%—Yajl-ruby Project Yajl-rubyDebian Linux11/3/20176/17/2026
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Orbitaley — Vulnerabilities