5
CVE-2014-9490
- EPSS 2.41%
- Veröffentlicht 20.01.2015 15:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Getsentry ≫ Raven-ruby SwPlatformruby Version <= 0.12.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.41% | 0.82 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
http://seclists.org/oss-sec/2015/q1/26
https://exchange.xforce.ibmcloud.com/vulnerabilities/99687
https://github.com/getsentry/raven-ruby/commit/477ee93a3f735be33bc1e726820654cdf6e22d8f
https://groups.google.com/forum/#%21topic/getsentry/Cz5bih0ZY1U