Логотип exploitDog
bind:CVE-2015-3900
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-3900

Количество 7

Количество 7

ubuntu логотип

CVE-2015-3900

больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-3900

больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

CVSS2: 7.9
EPSS: Низкий
nvd логотип

CVE-2015-3900

больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-3900

больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4 ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-wp3j-rvfp-624h

больше 3 лет назад

RubyGems vulnerable to DNS hijack attack

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:1128-1

почти 9 лет назад

Security update for ruby2.1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:1067-1

почти 9 лет назад

Security update for ruby2.1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-3900

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

CVSS2: 5
2%
Низкий
больше 10 лет назад
redhat логотип
CVE-2015-3900

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

CVSS2: 7.9
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-3900

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

CVSS2: 5
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-3900

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4 ...

CVSS2: 5
2%
Низкий
больше 10 лет назад
github логотип
GHSA-wp3j-rvfp-624h

RubyGems vulnerable to DNS hijack attack

2%
Низкий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2017:1128-1

Security update for ruby2.1

почти 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:1067-1

Security update for ruby2.1

почти 9 лет назад

Уязвимостей на страницу