Known vulnerabilities in ruby2.5-stdlib
Vendor:
SUSE
Software:
ruby2.5-stdlib
Software CPE:
cpe:2.3:o:suse:ruby2.5-stdlib:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
27
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (27)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU126646 - Buffer overflow CVE-2026-27820 |
CWE-120 | High | 2.5.9-150700.24.6.1 | 21.04.2026 |
SB2026042132 SB2026042133 |
||
| #VU126644 - Improper Access Control CVE-2026-41316 |
CWE-284 | High | 2.5.9-150700.24.11.1 | 21.04.2026 |
SB2026042131 SB20260509132 SB2026051815 and 10 more |
||
| #VU115794 - Resource exhaustion CVE-2025-58767 |
CWE-400 | Low | 2.5.9-150700.24.6.1 | 18.09.2025 |
SB2025091868 SB2025102434 SB2025110338 and 12 more |
||
| #VU114812 - Resource exhaustion CVE-2025-24294 |
CWE-400 | Medium | 2.5.9-150000.4.54.1, 2.5.9-150700.24.3.1 | 04.09.2025 |
SB2025090467 SB2025090470 SB2025090473 and 10 more |
||
| #VU114416 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-6442 |
CWE-444 | Medium | 2.5.9-150000.4.46.1, 2.5.9-150700.24.3.1 | 25.08.2025 |
SB2024100844 SB2025082565 SB2025082567 and 10 more |
||
| #VU105107 - Inefficient Regular Expression Complexity CVE-2025-27220 |
CWE-1333 | Medium | 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1 | 27.02.2025 |
SB20250227242 SB2025030761 SB2025031451 and 9 more |
||
| #VU105106 - Improper input validation CVE-2025-27219 |
CWE-20 | Medium | 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1 | 27.02.2025 |
SB20250227242 SB2025030761 SB2025031451 and 15 more |
||
| #VU105105 - Exposure of sensitive information to an unauthorized actor CVE-2025-27221 |
CWE-200 | Medium | 2.5.9-150000.4.46.1, 2.5.9-150700.24.3.1 | 27.02.2025 |
SB20250227241 SB2025030761 SB2025031451 and 16 more |
||
| #VU99358 - Inefficient Regular Expression Complexity CVE-2024-49761 |
CWE-1333 | Medium | 2.5.9-150000.4.36.1, 2.5.9-150700.24.3.1, 2.5.9-150700.24.6.1 | 28.10.2024 |
SB2024102837 SB2024110504 SB20241108111 and 38 more |
||
| #VU98142 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-47220 |
CWE-444 | Medium | 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1 | 08.10.2024 |
SB2024100844 SB2024100847 SB2024100853 and 16 more |
||
| #VU96998 - Improper input validation CVE-2024-35221 |
CWE-20 | Medium | 2.5.9-150000.4.49.1, 2.5.9-150700.24.3.1 | 10.09.2024 |
SB2024091055 SB2024091063 SB2024091070 and 4 more |
||
| #VU96970 - Resource exhaustion CVE-2024-43398 |
CWE-400 | Medium | 2.5.9-150000.4.32.1 | 10.09.2024 |
SB2024091006 SB2024091007 SB2024091008 and 28 more |
||
| #VU95149 - Improper input validation CVE-2024-41123 |
CWE-20 | Medium | 2.5.9-150000.4.32.1 | 01.08.2024 |
SB2024080145 SB2024091009 SB2024091607 and 24 more |
||
| #VU95148 - Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') CVE-2024-41946 |
CWE-776 | Medium | 2.5.9-150000.4.32.1 | 01.08.2024 |
SB2024080145 SB2024082374 SB2024091607 and 22 more |
||
| #VU94363 - Improper input validation CVE-2024-39908 |
CWE-20 | Medium | 2.5.9-150000.4.32.1 | 16.07.2024 |
SB2024071616 SB2024083015 SB2024091009 and 22 more |
||
| #VU94361 - Improper input validation CVE-2024-35176 |
CWE-20 | Medium | 2.5.9-150000.4.32.1 | 16.07.2024 |
SB2024071615 SB2024071914 SB2024072112 and 19 more |
||
| #VU74007 - Incorrect Regular Expression CVE-2023-28756 |
CWE-185 | Medium | 2.5.9-150000.4.29.1 | 24.03.2023 |
SB2023033146 SB2023050430 SB2023051746 and 33 more |
||
| #VU74004 - Incorrect Regular Expression CVE-2023-28755 |
CWE-185 | Medium | 2.5.9-150000.4.29.1 | 24.03.2023 |
SB2023033146 SB2023042108 SB2023050430 and 41 more |
||
| #VU69506 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2021-33621 |
CWE-113 | Medium | 2.5.9-150000.4.29.1 | 22.11.2022 |
SB2022112239 SB2022112439 SB2023011730 and 31 more |
||
| #VU58365 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2021-41819 |
CWE-451 | Medium | 2.5.9-150000.4.26.1 | 25.11.2021 |
SB2021112503 SB2022011920 SB2022020413 and 21 more |
Showing elements 1 - 20 out of 27