Known vulnerabilities in ruby-rack (Ubuntu package) - page 2

Software CPE: cpe:2.3:o:canonical:ruby-rack_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 39
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ruby-rack (Ubuntu package) ruby-rack (Ubuntu package) is affected by 39 known vulnerabilities: 2 high, 32 medium, 5 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116144 - Resource exhaustion
CVE-2025-59830
CWE-400 High
No
No
1.6.4-3ubuntu0.2+esm9, 1.6.4-4ubuntu0.2+esm9, 2.0.7-2ubuntu0.1+esm8, 2.1.4-5ubuntu1.2, 2.2.7-1ubuntu0.4, 2.2.7-1ubuntu0.5, 2.2.7-1.1ubuntu0.25.04.3, 3.1.16-0.1ubuntu0.1 26.09.2025 SB2025092633
SB2025093022
SB2025110346
and 14 more
#VU111989 - Resource exhaustion
CVE-2025-46727
CWE-400 Medium
No
No
1.5.2-3+deb8u3ubuntu1~esm10, 1.6.4-3ubuntu0.2+esm8, 1.6.4-4ubuntu0.2+esm8, 2.0.7-2ubuntu0.1+esm7, 2.1.4-5ubuntu1.1+esm2, 2.2.7-1ubuntu0.3, 2.2.7-1.1ubuntu0.25.04.1 27.06.2025 SB2025062709
SB2025062710
SB2025062711
and 24 more
#VU111976 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-32441
CWE-362 Low
No
No
1.5.2-3+deb8u3ubuntu1~esm10, 1.6.4-3ubuntu0.2+esm8, 1.6.4-4ubuntu0.2+esm8, 2.0.7-2ubuntu0.1+esm7, 2.1.4-5ubuntu1.1+esm2, 2.2.7-1ubuntu0.3, 2.2.7-1.1ubuntu0.25.04.1 26.06.2025 SB2025062650
SB2025062720
SB2025062721
and 5 more
#VU105796 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-27610
CWE-22 Medium
No
No
Ubuntu Pro, 2.2.7-1ubuntu0.2, 2.2.7-1.1ubuntu0.1, 2.2.7-1.1ubuntu0.25.04.2 17.03.2025 SB2025031756
SB20250317118
SB20250317119
and 15 more
#VU105795 - Improper Output Neutralization for Logs
CVE-2025-27111
CWE-117 Medium
No
No
Ubuntu Pro, 2.2.7-1ubuntu0.2, 2.2.7-1.1ubuntu0.1, 2.2.7-1.1ubuntu0.25.04.2 17.03.2025 SB2025031755
SB20250317119
SB2025031840
and 10 more
#VU105794 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2025-25184
CWE-93 Low
No
No
Ubuntu Pro, 2.2.7-1ubuntu0.2, 2.2.7-1.1ubuntu0.1, 2.2.7-1.1ubuntu0.25.04.2 17.03.2025 SB2025031754
SB2025031758
SB20250317118
and 8 more
#VU87010 - Incorrect Regular Expression
CVE-2024-25126
CWE-185 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1, 2.2.4-3ubuntu0.2, 2.2.7-1ubuntu0.1 04.03.2024 SB2024030429
SB2024030544
SB2024041627
and 21 more
#VU87009 - Improper input validation
CVE-2024-26141
CWE-20 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1, 2.2.4-3ubuntu0.1, 2.2.4-3ubuntu0.2, 2.2.7-1ubuntu0.1 04.03.2024 SB2024030429
SB2024030544
SB2024031240
and 22 more
#VU87008 - Improper input validation
CVE-2024-26146
CWE-20 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1, 2.2.4-3ubuntu0.1, 2.2.4-3ubuntu0.2, 2.2.7-1ubuntu0.1 04.03.2024 SB2024030428
SB2024030544
SB2024031240
and 21 more
#VU74199 - Improper input validation
CVE-2023-27539
CWE-20 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1, 2.2.4-3ubuntu0.1 30.03.2023 SB2023033030
SB2023033041
SB2023041727
and 18 more
#VU73726 - Improper input validation
CVE-2023-27530
CWE-20 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1, 2.2.4-3ubuntu0.2, 2.2.7-1ubuntu0.1 15.03.2023 SB2023031545
SB2023031551
SB2023042535
and 18 more
#VU71978 - Resource exhaustion
CVE-2022-44572
CWE-400 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1 07.02.2023 SB2023020708
SB2023020711
SB2023030241
and 10 more
#VU71977 - Resource exhaustion
CVE-2022-44571
CWE-400 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1 07.02.2023 SB2023020708
SB2023020711
SB2023030241
and 11 more
#VU71974 - Resource exhaustion
CVE-2022-44570
CWE-400 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1 07.02.2023 SB2023020708
SB2023020711
SB2023030241
and 11 more
#VU67622 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-8161
CWE-22 Medium
No
No
1.6.4-3ubuntu0.2, 1.6.4-4ubuntu0.2, 2.0.7-2ubuntu0.1, 2.1.1-5ubuntu0.1 23.09.2022 SB2020070234
SB2022092345
SB2021040632
and 3 more
#VU67621 - Missing Support for Integrity Check
CVE-2020-8184
CWE-353 Low
No
No
1.6.4-3ubuntu0.2, 1.6.4-4ubuntu0.2, 2.0.7-2ubuntu0.1, 2.1.1-5ubuntu0.1 23.09.2022 SB2022070222
SB2022092345
SB2021040632
and 5 more
#VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30123
CWE-78 High
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 14 more
#VU64862 - Improper input validation
CVE-2022-30122
CWE-20 Medium
No
No
Ubuntu Pro, 2.1.4-5ubuntu1.1 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 8 more
#VU15970 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-16471
CWE-79 Low
No
No
1.6.4-3ubuntu0.1, 1.6.4-4ubuntu0.1 19.11.2018 SB2018112007
SB2019061306
SB2019080807
and 4 more


Showing elements 21 - 40 out of 39