Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 38

Количество 38

redos логотип

ROS-20250417-13

больше 1 года назад

Уязвимость ruby

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-25186

больше 1 года назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2025-25186

больше 1 года назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-25186

больше 1 года назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2025-25186

5 месяцев назад

Net::IMAP vulnerable to possible DoS by memory exhaustion

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-25186

больше 1 года назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-27219

больше 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2025-27219

больше 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-27219

больше 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
EPSS: Низкий
msrc логотип

CVE-2025-27219

больше 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-27219

больше 1 года назад

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in ...

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-7fc5-f82f-cx69

больше 1 года назад

Possible DoS by memory exhaustion in net-imap

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gh9q-2xrm-x6qv

больше 1 года назад

CGI has Denial of Service (DoS) potential in Cookie.parse

CVSS3: 5.8
EPSS: Низкий
fstec логотип

BDU:2025-05128

больше 1 года назад

Уязвимость программного средства cgi gem, связанная с неправильная проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2025:4487

около 1 года назад

Moderate: ruby security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-4487

около 1 года назад

ELSA-2025-4487: ruby security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1369-1

больше 1 года назад

Security update for ruby2.5

EPSS: Низкий
redos логотип

ROS-20250417-12

больше 1 года назад

Множественные уязвимости ruby

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20250417-13

Уязвимость ruby

CVSS3: 5.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-25186

Net::IMAP vulnerable to possible DoS by memory exhaustion

CVSS3: 6.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

CVSS3: 6.5
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.8
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in ...

CVSS3: 5.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-7fc5-f82f-cx69

Possible DoS by memory exhaustion in net-imap

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-gh9q-2xrm-x6qv

CGI has Denial of Service (DoS) potential in Cookie.parse

CVSS3: 5.8
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-05128

Уязвимость программного средства cgi gem, связанная с неправильная проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 1 года назад
rocky логотип
RLSA-2025:4487

Moderate: ruby security update

около 1 года назад
oracle-oval логотип
ELSA-2025-4487

ELSA-2025-4487: ruby security update (MODERATE)

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1369-1

Security update for ruby2.5

больше 1 года назад
redos логотип
ROS-20250417-12

Множественные уязвимости ruby

CVSS3: 7.5
больше 1 года назад

Уязвимостей на страницу