Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  RUBY : Ruby 1.9
  RUBYGNOME : RubyGnome2 0.16
  RUBY : Ruby on Rails 1.2
  RUBYONRAILS : Ruby on Rails 1.1
  RUBY : Ruby 1.6
Name:RUBY : ruby 1.8

6!ruby multiple security vulnerabilities
document Crossite scripting, privilege escalation, Exception#to_s method data modification, VpMemAlloc memory corruption.
 Ruby DoS
document Crash on oversized string in BigDecimal.
6!Ruby multiple security vulnerabilities
updated since 27.06.2008
   
 Ruby WEBrick Web server Toolkit directory traversal
document Directory traversal with backslash.
6!Ruby Net::HTTPS library certificates validation cryptographic vulnerability
document Certificate's CN field is not validated against DNS name, making it's possible to use valid certificate with wrong CN.
 ruby DoS
updated since 05.11.2006
document SPU axhaustion in CGI library on parsing HTTP request with invalid MIME booundaries.
 Ruby Safe Level security bypass
updated since 12.07.2006
document "alias" can be exploited to replace safe function, directory access protection bypass. Few potentially dangerous methods are not limited.
 Ruby safe level protection bypass
document Error in eval.c in enforcing safe level protection.
 Ruby object-oriented language protection bypass
updated since 22.06.2005
document Error in XMLRPC module.
 Ruby symbolic links problem
document CGI::Session unsecurely creates temporary file.
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server