Логотип exploitDog
bind:"CVE-2014-8090" OR bind:"CVE-2014-4975" OR bind:"CVE-2014-8080"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2014-8090" OR bind:"CVE-2014-4975" OR bind:"CVE-2014-8080"

Количество 20

Количество 20

oracle-oval логотип

ELSA-2014-1913

больше 9 лет назад

ELSA-2014-1913: ruby193-ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1912

почти 11 лет назад

ELSA-2014-1912: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2014-1911

почти 11 лет назад

ELSA-2014-1911: ruby security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-8090

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x befo ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-2x97-vvh4-m4q4

больше 3 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

EPSS: Низкий
ubuntu логотип

CVE-2014-8080

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-8080

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-8080

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-8080

почти 11 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-4975

почти 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-4975

около 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2014-4975

почти 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-4975

почти 11 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and e ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-ggvr-v7qh-jwjh

больше 3 лет назад

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

EPSS: Низкий
github логотип

GHSA-gxj7-mcpg-jpr6

больше 3 лет назад

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1128-1

больше 8 лет назад

Security update for ruby2.1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1067-1

больше 8 лет назад

Security update for ruby2.1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2014-1913

ELSA-2014-1913: ruby193-ruby security update (MODERATE)

больше 9 лет назад
oracle-oval логотип
ELSA-2014-1912

ELSA-2014-1912: ruby security update (MODERATE)

почти 11 лет назад
oracle-oval логотип
ELSA-2014-1911

ELSA-2014-1911: ruby security update (MODERATE)

почти 11 лет назад
ubuntu логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
9%
Низкий
почти 11 лет назад
redhat логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 4.3
9%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

CVSS2: 5
9%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-8090

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x befo ...

CVSS2: 5
9%
Низкий
почти 11 лет назад
github логотип
GHSA-2x97-vvh4-m4q4

The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nested entity references, aka an XML Entity Expansion (XEE) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1821 and CVE-2014-8080.

9%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2014-8080

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 5
10%
Низкий
почти 11 лет назад
redhat логотип
CVE-2014-8080

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 4.3
10%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-8080

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 5
10%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-8080

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p ...

CVSS2: 5
10%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-4975

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

CVSS2: 5
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2014-4975

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

CVSS2: 2.6
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-4975

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

CVSS2: 5
2%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-4975

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and e ...

CVSS2: 5
2%
Низкий
почти 11 лет назад
github логотип
GHSA-ggvr-v7qh-jwjh

The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-gxj7-mcpg-jpr6

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that trigger a stack-based buffer overflow.

2%
Низкий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1128-1

Security update for ruby2.1

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:1067-1

Security update for ruby2.1

больше 8 лет назад

Уязвимостей на страницу