Vulnerabilidades en Ruby

35 resultados
Análisis Vexday

Ruby registra 9 vulnerabilidades na base do Vexday, todas de severidade abaixo de crítica, sem exploração ativa documentada (KEV). A fraqueza dominante é CWE-400 (controle inadequado de recursos), indicando risco moderado de negação de serviço; a ausência de atualizações nos últimos 90 dias sugere que as ameaças conhecidas não evoluíram recentemente, mantendo o panorama estável.

CVE-2025-24294HIGHThe attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressEPSS 0.6%CVE-2026-27820LOWzlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruptionEPSS 0.6%CVE-2026-47240MEDIUMNet::IMAP: Command Injection via non-synchronizing literal in "raw" argumentEPSS 0.5%CVE-2025-6442MEDIUMRuby WEBrick read_header HTTP Request Smuggling VulnerabilityEPSS 0.5%CVE-2025-43857MEDIUMnet-imap rubygem vulnerable to possible DoS by memory exhaustionEPSS 0.5%CVE-2026-42257MEDIUMnet-imap: Command Injection via "raw" arguments to multiple commandsEPSS 0.4%CVE-2026-42245LOWnet-imap: Quadratic complexity when reading response literalsEPSS 0.4%CVE-2026-71847HIGHRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streamsEPSS 0.4%CVE-2026-54696LOWRuby JSON: JSON generator heap buffer overflow when streaming to an IOEPSS 0.4%CVE-2026-80213MEDIUMAn issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet EPSS 0.4%CVE-2026-42246HIGHnet-imap vulnerable to STARTTLS stripping via invalid response timingEPSS 0.3%CVE-2026-42256MEDIUMnet-imap: Denial of service via high iteration count for `SCRAM-*` authenticationEPSS 0.3%CVE-2025-58767LOWREXML has a DoS condition when parsing malformed XML fileEPSS 0.2%CVE-2026-47241LOWNet::IMAP: Denial of Service via incomplete raw argument validationEPSS 0.2%CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.1%