Known vulnerabilities in ruby2.5 (Ubuntu package) - page 2
Vendor:
Canonical Ltd.
Software:
ruby2.5 (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:ruby2.5_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
29
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.5.1-1ubuntu1.16+esm5
2.7.0-5ubuntu1.18+esm1
3.0.2-7ubuntu2.11
3.2.3-1ubuntu0.24.04.6
3.3.7-1ubuntu2.1
Ubuntu Pro
2.5.1-1ubuntu1.16
2.5.1-1ubuntu1.15
2.5.1-1ubuntu1.14
2.5.1-1ubuntu1.13
2.5.1-1ubuntu1.12
2.5.1-1ubuntu1.11
2.5.1-1ubuntu1.10
2.5.1-1ubuntu1.9
2.5.1-1ubuntu1.8
2.5.1-1ubuntu1.7
2.5.5
2.5.1
2.5.7-1ubuntu4
2.5.7-1ubuntu2
2.5.7-1ubuntu3
2.5.7-1
2.5.7-1ubuntu1
2.5.5-4ubuntu2.1
2.5.5-1ubuntu1.1
2.5.1-1ubuntu1.6
2.5.5-4
2.5.5-3
2.5.5-3ubuntu1
2.5.5-2
2.5.5-2ubuntu1
2.5.1-1ubuntu1.4
2.5.5-4ubuntu2
2.5.5-4ubuntu1
2.5.1-1ubuntu1.5
2.5.5-1
2.5.5-1ubuntu1
2.5.3-4
2.5.3-4ubuntu1
2.5.1-5ubuntu4.3
2.5.1-1ubuntu1.2
2.5.1-5ubuntu4.2
2.5.3-3ubuntu3
2.5.3-3ubuntu2
2.5.0~preview1-1ubuntu1
2.5.3-1
2.5.3-2
2.5.3-3
2.5.3-3ubuntu1
2.5.1-6ubuntu3
2.5.1-6ubuntu2
2.5.1-6
2.5.1-6ubuntu1
2.5.1-5ubuntu4
2.5.1-5ubuntu4.1
2.5.1-5ubuntu2
2.5.1-5ubuntu3
2.5.1-5ubuntu1
2.5.1-2
2.5.1-3
2.5.1-4
2.5.1-5
2.5.1-1
2.5.1-1ubuntu1
2.5.1-1ubuntu1.1
2.5.0-5
2.5.0-5ubuntu1
2.5.0-6
2.5.0-6ubuntu1
2.5.0-4ubuntu4
2.5.0-4ubuntu3
2.5.0-4ubuntu2
2.5.0~preview1-1
2.5.0~preview1-1ubuntu2
2.5.0~rc1-1
2.5.0-1
2.5.0-2
2.5.0-3
2.5.0-4
2.5.0-4ubuntu1
Vulnerabilities (29)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU55489 - Improper Certificate Validation CVE-2021-32066 |
CWE-295 | Medium | 2.5.1-1ubuntu1.10 | 02.08.2021 |
SB2021080209 SB2021080210 SB2021080913 and 28 more |
||
| #VU52000 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-28965 |
CWE-611 | Medium | 2.5.1-1ubuntu1.9 | 08.04.2021 |
SB2021040816 SB2021041365 SB2021042119 and 24 more |
||
| #VU47333 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-25613 |
CWE-444 | Medium | 2.5.1-1ubuntu1.8 | 05.10.2020 |
SB2020100509 SB2020100703 SB2020111806 and 21 more |
||
| #VU31886 - Exposure of sensitive information to an unauthorized actor CVE-2020-10933 |
CWE-200 | Low | 2.5.1-1ubuntu1.8 | 26.07.2020 |
SB2020050439 SB2020050208 SB2020040188 and 11 more |
||
| #VU32971 - Improper input validation CVE-2020-10663 |
CWE-20 | Medium | 2.5.1-1ubuntu1.8 | 28.04.2020 |
SB2020042868 SB2020050208 SB2020081273 and 24 more |
||
| #VU23009 - Improper Control of Generation of Code ('Code Injection') CVE-2019-16255 |
CWE-94 | High | 2.5.1-1ubuntu1.6, 2.5.5-1ubuntu1.1, 2.5.5-4ubuntu2.1 | 27.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 14 more |
||
| #VU23008 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2019-16254 |
CWE-113 | Medium | 2.5.1-1ubuntu1.6, 2.5.5-1ubuntu1.1, 2.5.5-4ubuntu2.1 | 27.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 14 more |
||
| #VU23007 - Improper input validation CVE-2019-16201 |
CWE-20 | Medium | 2.5.1-1ubuntu1.6, 2.5.5-1ubuntu1.1, 2.5.5-4ubuntu2.1 | 27.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 14 more |
||
| #VU23006 - Improper input validation CVE-2019-15845 |
CWE-20 | Medium | 2.5.1-1ubuntu1.6, 2.5.5-1ubuntu1.1, 2.5.5-4ubuntu2.1 | 26.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 15 more |
Showing elements 21 - 40 out of 29