Search CVE reports


Toggle filters

61 – 62 of 62 results


CVE-2018-1000073

Low priority

Some fixes available 4 of 10

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory...

6 affected packages

ruby2.1, jruby, ruby1.9.1, ruby2.0, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby2.1 Not in release Not in release Not in release Not in release
jruby Not affected Not affected Needs evaluation
ruby1.9.1 Not in release Not in release Not in release Not in release
ruby2.0 Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Fixed
Show less packages

CVE-2017-17790

Medium priority

Some fixes available 4 of 5

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different...

3 affected packages

ruby2.5, ruby1.9.1, ruby2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby2.5 Fixed
ruby1.9.1 Not in release
ruby2.3 Not in release
Show less packages