Known vulnerabilities in REXML 3.3.1
Vendor:
rubygems.org
Software:
REXML
Version:
3.3.1
Software CPE:
cpe:2.3:a:rubygems.org:rexml:*:*:*:*:*:*:*:*
Website:
https://rubygems.org
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU99358 - Inefficient Regular Expression Complexity CVE-2024-49761 |
CWE-1333 | Medium | 3.3.9 | 28.10.2024 |
SB2024102837 SB2024110504 SB20241108111 and 38 more |
||
| #VU96970 - Resource exhaustion CVE-2024-43398 |
CWE-400 | Medium | 3.3.6 | 10.09.2024 |
SB2024091006 SB2024091007 SB2024091008 and 28 more |
||
| #VU95149 - Improper input validation CVE-2024-41123 |
CWE-20 | Medium | 3.3.3 | 01.08.2024 |
SB2024080145 SB2024091009 SB2024091607 and 24 more |
||
| #VU95148 - Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') CVE-2024-41946 |
CWE-776 | Medium | 3.3.3 | 01.08.2024 |
SB2024080145 SB2024082374 SB2024091607 and 22 more |
||
| #VU94363 - Improper input validation CVE-2024-39908 |
CWE-20 | Medium | 3.3.2 | 16.07.2024 |
SB2024071616 SB2024083015 SB2024091009 and 22 more |