Known vulnerabilities in ruby-devel - page 2

Vendor: OpenAnolis
Software: ruby-devel
Software CPE: cpe:2.3:o:openanolis:ruby-devel:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 35
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ruby-devel ruby-devel is affected by 35 known vulnerabilities: 8 high, 24 medium, 3 low Critical High Medium Low

Vulnerabilities (35)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77803 - Incorrect Regular Expression
CVE-2023-36617
CWE-185 Medium
No
No
2.5.9-112.0.1, 3.1.4-9 29.06.2023 SB2023062931
SB2023071289
SB2023101967
and 13 more
#VU74007 - Incorrect Regular Expression
CVE-2023-28756
CWE-185 Medium
No
No
2.5.9-111.0.1, 2.7.8-139, 3.0.7-143.0.1 24.03.2023 SB2023033146
SB2023050430
SB2023051746
and 33 more
#VU74004 - Incorrect Regular Expression
CVE-2023-28755
CWE-185 Medium
No
No
2.5.9-111.0.1, 2.5.9-112.0.1, 2.7.8-139, 3.0.7-143.0.1, 3.1.4-9 24.03.2023 SB2023033146
SB2023042108
SB2023050430
and 41 more
#VU69506 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2021-33621
CWE-113 Medium
No
No
2.5.9-111.0.1, 2.7.8-139, 3.0.7-143.0.1 22.11.2022 SB2022112239
SB2022112439
SB2023011730
and 31 more
#VU62081 - Type conversion
CVE-2022-28739
CWE-704 High
No
No
2.5.9-111.0.1, 2.6.10-109, 2.7.6-138.0.1, 3.0.4-141.0.1 12.04.2022 SB2022041215
SB2022041404
SB2022060704
and 28 more
#VU62080 - Double Free
CVE-2022-28738
CWE-415 High
No
No
3.0.4-141.0.1 12.04.2022 SB2022041215
SB2022041404
SB2022060704
and 13 more
#VU59824 - Incorrect Regular Expression
CVE-2021-41817
CWE-185 Medium
No
No
2.5.9-110.0.1, 2.6.9-108, 2.7.6-138.0.1, 3.0.4-141.0.1 19.01.2022 SB2022011919
SB2022011920
SB2022020413
and 24 more
#VU58365 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-41819
CWE-451 Medium
No
No
2.5.9-110.0.1, 2.6.9-108, 2.7.6-138.0.1, 3.0.4-141.0.1 25.11.2021 SB2021112503
SB2022011920
SB2022020413
and 21 more
#VU55666 - Insufficient Verification of Data Authenticity
CVE-2020-36327
CWE-345 High
No
No
2.6.9-108, 2.7.4-137 09.08.2021 SB2021080910
SB2021080913
SB2021092218
and 21 more
#VU55489 - Improper Certificate Validation
CVE-2021-32066
CWE-295 Medium
No
No
2.5.9-109.0.1, 2.6.9-108, 2.7.4-137 02.08.2021 SB2021080209
SB2021080210
SB2021080913
and 28 more
#VU55488 - Exposure of sensitive information to an unauthorized actor
CVE-2021-31810
CWE-200 Medium
No
No
2.5.9-109.0.1, 2.6.9-108, 2.7.4-137 02.08.2021 SB2021080209
SB2021080210
SB2021080913
and 27 more
#VU52796 - Command injection
CVE-2021-31799
CWE-77 High
No
No
2.5.9-109.0.1, 2.6.9-108, 2.7.4-137 03.05.2021 SB2021050306
SB2021052413
SB2021052414
and 27 more
#VU52000 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-28965
CWE-611 Medium
No
No
2.7.3-136 08.04.2021 SB2021040816
SB2021041365
SB2021042119
and 24 more
#VU50511 - Improper input validation
CVE-2021-24105
CWE-20 High
No
No
2.6.9-108, 2.7.4-137 09.02.2021 SB2021020965
SB2021070316
SB2021082548
and 2 more
#VU47333 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-25613
CWE-444 Medium
Available
No
2.7.3-136 05.10.2020 SB2020100509
SB2020100703
SB2020111806
and 21 more


Showing elements 21 - 40 out of 35