Логотип exploitDog
bind:"CVE-2025-25186" OR bind:"CVE-2025-27219" OR bind:"CVE-2025-27221"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-25186" OR bind:"CVE-2025-27219" OR bind:"CVE-2025-27221"

Количество 38

Количество 38

rocky логотип

RLSA-2025:8131

3 месяца назад

Moderate: ruby security update

EPSS: Низкий
rocky логотип

RLSA-2025:4493

5 месяцев назад

Moderate: ruby:3.3 security update

EPSS: Низкий
rocky логотип

RLSA-2025:10217

5 месяцев назад

Moderate: ruby:3.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-8131

6 месяцев назад

ELSA-2025-8131: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4493

8 месяцев назад

ELSA-2025-4493: ruby:3.3 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-10217

6 месяцев назад

ELSA-2025-10217: ruby:3.3 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2025-25186

10 месяцев назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2025-25186

10 месяцев назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-25186

10 месяцев назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2025-25186

8 месяцев назад

Net::IMAP vulnerable to possible DoS by memory exhaustion

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-25186

10 месяцев назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7fc5-f82f-cx69

10 месяцев назад

Possible DoS by memory exhaustion in net-imap

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2025:4488

5 месяцев назад

Moderate: ruby:3.1 security update

EPSS: Низкий
rocky логотип

RLSA-2025:4063

5 месяцев назад

Moderate: ruby:3.1 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4488

8 месяцев назад

ELSA-2025-4488: ruby:3.1 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4063

8 месяцев назад

ELSA-2025-4063: ruby:3.1 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4264-1

23 дня назад

Security update for ruby2.5

EPSS: Низкий
ubuntu логотип

CVE-2025-27221

10 месяцев назад

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2025-27221

10 месяцев назад

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

CVSS3: 3.2
EPSS: Низкий
nvd логотип

CVE-2025-27221

10 месяцев назад

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

CVSS3: 3.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2025:8131

Moderate: ruby security update

3 месяца назад
rocky логотип
RLSA-2025:4493

Moderate: ruby:3.3 security update

5 месяцев назад
rocky логотип
RLSA-2025:10217

Moderate: ruby:3.3 security update

5 месяцев назад
oracle-oval логотип
ELSA-2025-8131

ELSA-2025-8131: ruby security update (MODERATE)

6 месяцев назад
oracle-oval логотип
ELSA-2025-4493

ELSA-2025-4493: ruby:3.3 security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-10217

ELSA-2025-10217: ruby:3.3 security update (MODERATE)

6 месяцев назад
ubuntu логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
msrc логотип
CVE-2025-25186

Net::IMAP vulnerable to possible DoS by memory exhaustion

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-7fc5-f82f-cx69

Possible DoS by memory exhaustion in net-imap

CVSS3: 6.5
0%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:4488

Moderate: ruby:3.1 security update

5 месяцев назад
rocky логотип
RLSA-2025:4063

Moderate: ruby:3.1 security update

5 месяцев назад
oracle-oval логотип
ELSA-2025-4488

ELSA-2025-4488: ruby:3.1 security update (MODERATE)

8 месяцев назад
oracle-oval логотип
ELSA-2025-4063

ELSA-2025-4063: ruby:3.1 security update (MODERATE)

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4264-1

Security update for ruby2.5

23 дня назад
ubuntu логотип
CVE-2025-27221

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

CVSS3: 3.2
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2025-27221

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

CVSS3: 3.2
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-27221

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

CVSS3: 3.2
0%
Низкий
10 месяцев назад

Уязвимостей на страницу