Known vulnerabilities in ruby-doc - page 2
Vendor:
OpenAnolis
Software:
ruby-doc
Software CPE:
cpe:2.3:o:openanolis:ruby-doc:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
35
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.3.9-11
3.3.9-9
3.3.12-8
2.5.9-115.0.1
3.3.10-7
3.3.9-8
3.3.10-6
3.3.9-7
3.3.9-6
3.3.10-5
3.3.9-5
3.3.8-4
3.3.7-4
2.5.9-114.0.1
2.5.9-109.0.1
2.6.9-108
2.7.4-137
2.6.7-107.0.1
2.5.9-107
2.5.9-113.0.1
3.3.5-3
2.5.9-112.0.1
3.0.7-143.0.1
2.5.9-111.0.1
3.1.4-9
2.7.8-139
3.0.4-141.0.1
2.7.6-138.0.1
2.5.9-110.0.1
2.6.10-109
2.7.3-136
Vulnerabilities (35)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU77803 - Incorrect Regular Expression CVE-2023-36617 |
CWE-185 | Medium | 2.5.9-112.0.1, 3.1.4-9 | 29.06.2023 |
SB2023062931 SB2023071289 SB2023101967 and 13 more |
||
| #VU74007 - Incorrect Regular Expression CVE-2023-28756 |
CWE-185 | Medium | 2.5.9-111.0.1, 2.7.8-139, 3.0.7-143.0.1 | 24.03.2023 |
SB2023033146 SB2023050430 SB2023051746 and 33 more |
||
| #VU74004 - Incorrect Regular Expression CVE-2023-28755 |
CWE-185 | Medium | 2.5.9-111.0.1, 2.5.9-112.0.1, 2.7.8-139, 3.0.7-143.0.1, 3.1.4-9 | 24.03.2023 |
SB2023033146 SB2023042108 SB2023050430 and 41 more |
||
| #VU69506 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2021-33621 |
CWE-113 | Medium | 2.5.9-111.0.1, 2.7.8-139, 3.0.7-143.0.1 | 22.11.2022 |
SB2022112239 SB2022112439 SB2023011730 and 31 more |
||
| #VU62081 - Type conversion CVE-2022-28739 |
CWE-704 | High | 2.5.9-111.0.1, 2.6.10-109, 2.7.6-138.0.1, 3.0.4-141.0.1 | 12.04.2022 |
SB2022041215 SB2022041404 SB2022060704 and 28 more |
||
| #VU62080 - Double Free CVE-2022-28738 |
CWE-415 | High | 3.0.4-141.0.1 | 12.04.2022 |
SB2022041215 SB2022041404 SB2022060704 and 13 more |
||
| #VU59824 - Incorrect Regular Expression CVE-2021-41817 |
CWE-185 | Medium | 2.5.9-110.0.1, 2.6.9-108, 2.7.6-138.0.1, 3.0.4-141.0.1 | 19.01.2022 |
SB2022011919 SB2022011920 SB2022020413 and 24 more |
||
| #VU58365 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2021-41819 |
CWE-451 | Medium | 2.5.9-110.0.1, 2.6.9-108, 2.7.6-138.0.1, 3.0.4-141.0.1 | 25.11.2021 |
SB2021112503 SB2022011920 SB2022020413 and 21 more |
||
| #VU55666 - Insufficient Verification of Data Authenticity CVE-2020-36327 |
CWE-345 | High | 2.6.9-108, 2.7.4-137 | 09.08.2021 |
SB2021080910 SB2021080913 SB2021092218 and 21 more |
||
| #VU55489 - Improper Certificate Validation CVE-2021-32066 |
CWE-295 | Medium | 2.5.9-109.0.1, 2.6.9-108, 2.7.4-137 | 02.08.2021 |
SB2021080209 SB2021080210 SB2021080913 and 28 more |
||
| #VU55488 - Exposure of sensitive information to an unauthorized actor CVE-2021-31810 |
CWE-200 | Medium | 2.5.9-109.0.1, 2.6.9-108, 2.7.4-137 | 02.08.2021 |
SB2021080209 SB2021080210 SB2021080913 and 27 more |
||
| #VU52796 - Command injection CVE-2021-31799 |
CWE-77 | High | 2.5.9-109.0.1, 2.6.9-108, 2.7.4-137 | 03.05.2021 |
SB2021050306 SB2021052413 SB2021052414 and 27 more |
||
| #VU52000 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-28965 |
CWE-611 | Medium | 2.7.3-136 | 08.04.2021 |
SB2021040816 SB2021041365 SB2021042119 and 24 more |
||
| #VU50511 - Improper input validation CVE-2021-24105 |
CWE-20 | High | 2.6.9-108, 2.7.4-137 | 09.02.2021 |
SB2021020965 SB2021070316 SB2021082548 and 2 more |
||
| #VU47333 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-25613 |
CWE-444 | Medium | 2.7.3-136 | 05.10.2020 |
SB2020100509 SB2020100703 SB2020111806 and 21 more |
Showing elements 21 - 40 out of 35