Known vulnerabilities in rubygems-devel - page 2
Vendor:
OpenAnolis
Software:
rubygems-devel
Software CPE:
cpe:2.3:o:openanolis:rubygems-devel:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
35
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.5.22-11
3.5.22-9
2.7.6.3-115.0.1
3.5.22-8
3.5.22-7
3.5.22-6
3.5.22-5
3.5.22-4
2.7.6.3-114.0.1
2.7.6.3-109.0.1
3.0.3.1-108
3.1.6-137
3.0.3.1-107.0.1
2.7.6.3-107
2.7.6.3-113.0.1
3.5.16-3
2.7.6.3-112.0.1
3.2.33-143.0.1
2.7.6.3-111.0.1
3.3.26-9
3.1.6-139
3.2.33-141.0.1
3.1.6-138.0.1
2.7.6.3-110.0.1
3.0.3.1-109
3.1.6-136
Vulnerabilities (35)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU77803 - Incorrect Regular Expression CVE-2023-36617 |
CWE-185 | Medium | 2.7.6.3-112.0.1, 3.3.26-9 | 29.06.2023 |
SB2023062931 SB2023071289 SB2023101967 and 13 more |
||
| #VU74007 - Incorrect Regular Expression CVE-2023-28756 |
CWE-185 | Medium | 2.7.6.3-111.0.1, 3.1.6-139, 3.2.33-143.0.1 | 24.03.2023 |
SB2023033146 SB2023050430 SB2023051746 and 33 more |
||
| #VU74004 - Incorrect Regular Expression CVE-2023-28755 |
CWE-185 | Medium | 2.7.6.3-111.0.1, 2.7.6.3-112.0.1, 3.1.6-139, 3.2.33-143.0.1, 3.3.26-9 | 24.03.2023 |
SB2023033146 SB2023042108 SB2023050430 and 41 more |
||
| #VU69506 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2021-33621 |
CWE-113 | Medium | 2.7.6.3-111.0.1, 3.1.6-139, 3.2.33-143.0.1 | 22.11.2022 |
SB2022112239 SB2022112439 SB2023011730 and 31 more |
||
| #VU62081 - Type conversion CVE-2022-28739 |
CWE-704 | High | 2.7.6.3-111.0.1, 3.0.3.1-109, 3.1.6-138.0.1, 3.2.33-141.0.1 | 12.04.2022 |
SB2022041215 SB2022041404 SB2022060704 and 28 more |
||
| #VU62080 - Double Free CVE-2022-28738 |
CWE-415 | High | 3.2.33-141.0.1 | 12.04.2022 |
SB2022041215 SB2022041404 SB2022060704 and 13 more |
||
| #VU59824 - Incorrect Regular Expression CVE-2021-41817 |
CWE-185 | Medium | 2.7.6.3-110.0.1, 3.0.3.1-108, 3.1.6-138.0.1, 3.2.33-141.0.1 | 19.01.2022 |
SB2022011919 SB2022011920 SB2022020413 and 24 more |
||
| #VU58365 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2021-41819 |
CWE-451 | Medium | 2.7.6.3-110.0.1, 3.0.3.1-108, 3.1.6-138.0.1, 3.2.33-141.0.1 | 25.11.2021 |
SB2021112503 SB2022011920 SB2022020413 and 21 more |
||
| #VU55666 - Insufficient Verification of Data Authenticity CVE-2020-36327 |
CWE-345 | High | 3.0.3.1-108, 3.1.6-137 | 09.08.2021 |
SB2021080910 SB2021080913 SB2021092218 and 21 more |
||
| #VU55489 - Improper Certificate Validation CVE-2021-32066 |
CWE-295 | Medium | 2.7.6.3-109.0.1, 3.0.3.1-108, 3.1.6-137 | 02.08.2021 |
SB2021080209 SB2021080210 SB2021080913 and 28 more |
||
| #VU55488 - Exposure of sensitive information to an unauthorized actor CVE-2021-31810 |
CWE-200 | Medium | 2.7.6.3-109.0.1, 3.0.3.1-108, 3.1.6-137 | 02.08.2021 |
SB2021080209 SB2021080210 SB2021080913 and 27 more |
||
| #VU52796 - Command injection CVE-2021-31799 |
CWE-77 | High | 2.7.6.3-109.0.1, 3.0.3.1-108, 3.1.6-137 | 03.05.2021 |
SB2021050306 SB2021052413 SB2021052414 and 27 more |
||
| #VU52000 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-28965 |
CWE-611 | Medium | 3.1.6-136 | 08.04.2021 |
SB2021040816 SB2021041365 SB2021042119 and 24 more |
||
| #VU50511 - Improper input validation CVE-2021-24105 |
CWE-20 | High | 3.0.3.1-108, 3.1.6-137 | 09.02.2021 |
SB2021020965 SB2021070316 SB2021082548 and 2 more |
||
| #VU47333 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-25613 |
CWE-444 | Medium | 3.1.6-136 | 05.10.2020 |
SB2020100509 SB2020100703 SB2020111806 and 21 more |
Showing elements 21 - 40 out of 35