Known vulnerabilities in ruby (Alpine package) - page 2

Software CPE: cpe:2.3:o:alpine:ruby_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 45
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ruby (Alpine package) ruby (Alpine package) is affected by 45 known vulnerabilities: 5 high, 17 medium, 23 low Critical High Medium Low

Vulnerabilities (45)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20193 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-8320
CWE-22 Low
No
No
2.4.6-r0 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 8 more
#VU20192 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8323
CWE-79 Low
No
No
2.4.6-r0 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20191 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8322
CWE-79 Low
No
No
2.4.6-r0 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20190 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8325
CWE-79 Low
No
No
2.4.6-r0 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20189 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8324
CWE-94 Medium
No
No
2.4.6-r0 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 11 more
#VU15725 - Improper input validation
CVE-2018-16396
CWE-20 Low
No
No
2.3.8-r0 06.11.2018 SB2018110603
SB2018112909
SB2018112910
and 13 more
#VU15724 - Improper input validation
CVE-2018-16395
CWE-20 Low
No
No
2.3.8-r0 06.11.2018 SB2018110603
SB2018112909
SB2018112910
and 15 more
#VU11542 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-8780
CWE-22 Low
No
No
2.3.7-r0 05.04.2018 SB2018033009
SB2018080117
SB2018103106
and 15 more
#VU11541 - Null Byte Interaction Error (Poison Null Byte)
CVE-2018-8779
CWE-626 Low
No
No
2.3.7-r0 05.04.2018 SB2018033009
SB2018080117
SB2018103106
and 12 more
#VU11540 - Exposure of sensitive information to an unauthorized actor
CVE-2018-8778
CWE-200 Low
No
No
2.3.7-r0 05.04.2018 SB2018033009
SB2018080117
SB2018103106
and 15 more
#VU11539 - Resource exhaustion
CVE-2018-8777
CWE-400 Low
No
No
2.3.7-r0 05.04.2018 SB2018033009
SB2018080117
SB2018103106
and 16 more
#VU11538 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-6914
CWE-22 Low
No
No
2.3.7-r0 05.04.2018 SB2018033009
SB2018080117
SB2018103106
and 12 more
#VU11537 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2017-17742
CWE-113 Low
No
No
2.3.7-r0 05.04.2018 SB2018033009
SB2018080117
SB2018103106
and 17 more
#VU9718 - Command injection
CVE-2017-17405
CWE-77 High
Available
No
2.2.9-r0 22.12.2017 SB2017121408
SB2017122207
SB2018010413
and 11 more
#VU32356 - Improper input validation
CVE-2015-7551
CWE-20 High
No
No
2.2.4-r0 24.03.2016 SB2016032404
SB2015121805
SB2017040522
and 4 more
#VU33816 - Improper input validation
CVE-2015-5200
CWE-20 High
No
No
2.2.3-r0 08.09.2015 SB2015091105
SB2015090215
SB2015090216
and 2 more
#VU33080 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2015-5199
CWE-22 High
No
No
2.2.3-r0 08.09.2015 SB2015091104
SB2015090215
SB2015090216
and 2 more
#VU33079 - Permissions, Privileges, and Access Controls
CVE-2015-5198
CWE-264 Low
No
No
2.2.3-r0 08.09.2015 SB2015091103
SB2015090215
SB2015090216
and 2 more
#VU32366 - Improper input validation
CVE-2015-4020
CWE-20 Medium
No
No
2.2.3-r0 25.08.2015 SB2015082508
SB2015120316
SB2015061601
and 2 more
#VU32365 - Security Features
CVE-2015-3900
CWE-254 Medium
No
No
2.0.0_p647-r0 24.06.2015 SB2015062405
SB2015120315
SB2015061601
and 5 more


Showing elements 21 - 40 out of 45