CVE-2026-79590
- EPSS 0.16%
- Veröffentlicht 10.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting...
CVE-2022-4996
- EPSS 0.48%
- Veröffentlicht 19.08.2026 23:45:07
- Zuletzt bearbeitet 21.08.2026 17:16:26
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been publi...
CVE-2026-1979
- EPSS 0.15%
- Veröffentlicht 06.02.2026 04:32:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The ex...
CVE-2025-13120
- EPSS 0.15%
- Veröffentlicht 13.11.2025 15:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the pu...
CVE-2025-12875
- EPSS 0.16%
- Veröffentlicht 07.11.2025 20:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/length can lead to out-of-bounds write. The attack ne...
CVE-2025-7207
- EPSS 0.22%
- Veröffentlicht 09.07.2025 00:02:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer...
CVE-2021-46023
- EPSS 0.78%
- Veröffentlicht 14.02.2023 16:15:11
- Zuletzt bearbeitet 20.03.2025 21:15:13
An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash.
CVE-2022-1934
- EPSS 0.4%
- Veröffentlicht 31.05.2022 03:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:47
Use After Free in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-1427
- EPSS 0.45%
- Veröffentlicht 23.04.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:42
Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
CVE-2022-1286
- EPSS 1.11%
- Veröffentlicht 10.04.2022 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:24
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.