Yukihiro Matsumoto

Ruby

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.27%
  • Veröffentlicht 06.12.2006 19:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote attackers to cause a denial of service (infinite loop) via crafted HTTP requests, a different issue than ...

  • EPSS 4.52%
  • Veröffentlicht 27.10.2006 18:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier...

  • EPSS 3.1%
  • Veröffentlicht 21.07.2006 14:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".

  • EPSS 13.21%
  • Veröffentlicht 20.04.2006 21:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.

  • EPSS 23.92%
  • Veröffentlicht 07.10.2005 23:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).

  • EPSS 8.76%
  • Veröffentlicht 20.06.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.

  • EPSS 1.12%
  • Veröffentlicht 01.03.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.

  • EPSS 0.06%
  • Veröffentlicht 20.10.2004 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.