CVE-2017-17742
- EPSS 1.15%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:18:34
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.
CVE-2018-6914
- EPSS 2.37%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:24
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files vi...
CVE-2018-8777
- EPSS 1.86%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of...
CVE-2018-8778
- EPSS 0.54%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method...
CVE-2018-8779
- EPSS 1.28%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
CVE-2018-8780
- EPSS 1.34%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional director...
- EPSS 2.21%
- Veröffentlicht 03.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:20
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
CVE-2018-0493
- EPSS 0.96%
- Veröffentlicht 03.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:20
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.
CVE-2018-4117
- EPSS 0.95%
- Veröffentlicht 03.04.2018 06:29:04
- Zuletzt bearbeitet 21.11.2024 04:06:47
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves ...
CVE-2017-7000
- EPSS 0.59%
- Veröffentlicht 03.04.2018 06:29:01
- Zuletzt bearbeitet 21.11.2024 03:30:56
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c...