Логотип exploitDog
bind:"CVE-2011-1005" OR bind:"CVE-2011-1004" OR bind:"CVE-2011-0188"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2011-1005" OR bind:"CVE-2011-1004" OR bind:"CVE-2011-0188"

Количество 17

Количество 17

oracle-oval логотип

ELSA-2011-0910

около 14 лет назад

ELSA-2011-0910: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-0909

около 14 лет назад

ELSA-2011-0909: ruby security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2011-1005

больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2011-1005

больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-1005

больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-1005

больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-h2rc-3ppq-6pjg

около 3 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

EPSS: Низкий
ubuntu логотип

CVE-2011-1004

больше 14 лет назад

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS2: 6.3
EPSS: Низкий
redhat логотип

CVE-2011-1004

больше 14 лет назад

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2011-1004

больше 14 лет назад

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS2: 6.3
EPSS: Низкий
debian логотип

CVE-2011-1004

больше 14 лет назад

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-4 ...

CVSS2: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2011-0188

больше 14 лет назад

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2011-0188

больше 14 лет назад

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2011-0188

больше 14 лет назад

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-0188

больше 14 лет назад

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Rub ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-6vch-6cgr-x9c3

около 3 лет назад

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

EPSS: Низкий
github логотип

GHSA-45wv-gc6w-fq7m

около 3 лет назад

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2011-0910

ELSA-2011-0910: ruby security update (MODERATE)

около 14 лет назад
oracle-oval логотип
ELSA-2011-0909

ELSA-2011-0909: ruby security update (MODERATE)

около 14 лет назад
ubuntu логотип
CVE-2011-1005

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

CVSS2: 5
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2011-1005

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-1005

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

CVSS2: 5
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-1005

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through ...

CVSS2: 5
3%
Низкий
больше 14 лет назад
github логотип
GHSA-h2rc-3ppq-6pjg

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

3%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS2: 6.3
0%
Низкий
больше 14 лет назад
redhat логотип
CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS2: 3.6
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

CVSS2: 6.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-1004

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-4 ...

CVSS2: 6.3
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-0188

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2011-0188

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

CVSS2: 5.1
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-0188

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-0188

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Rub ...

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
github логотип
GHSA-6vch-6cgr-x9c3

The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."

3%
Низкий
около 3 лет назад
github логотип
GHSA-45wv-gc6w-fq7m

The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу