This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:ruby-lang:ruby:1.8.5
Detail
VendorRuby-LangFirst view 2007-10-01
ProductRubyLast view 2008-12-08
Version1.8.5TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:ruby-lang:ruby

Activity : Yearly

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentification
7.82008-12-08CVE-2008-4310NetworkLowNone Requ...
5.82008-09-04CVE-2008-3905NetworkMediumNone Requ...
52008-08-14CVE-2008-3443NetworkLowNone Requ...
7.52008-08-12CVE-2008-3657NetworkLowNone Requ...
7.82008-08-12CVE-2008-3656NetworkLowNone Requ...
Hide | Show 4 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
7.52008-08-12CVE-2008-3655NetworkLowNone Requ...
52008-04-18CVE-2008-1891NetworkLowNone Requ...
52007-11-13CVE-2007-5770NetworkLowNone Requ...
4.32007-10-01CVE-2007-5162NetworkMediumNone Requ...

CWE : Common Weakness Enumeration

%idName
33% (3)CWE-399Resource Management Errors
33% (3)CWE-287Improper Authentication
11% (1)CWE-264Permissions, Privileges, and Access Controls
11% (1)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
11% (1)CWE-20Improper Input Validation

Oval Markup Language : Definitions

OvalIDName
oval:org.mitre.oval:def:10738The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS...
oval:org.mitre.oval:def:11025The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) N...
oval:org.mitre.oval:def:9570The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 thro...
oval:org.mitre.oval:def:11602Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, an...
oval:org.mitre.oval:def:9682Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_v...
Hide | Show 3 More...
idName
oval:org.mitre.oval:def:9793The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 thro...
oval:org.mitre.oval:def:10034resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1....
oval:org.mitre.oval:def:10250httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterpris...

Open Source Vulnerability Database (OSVDB)

idDescription
47800Ruby Regexp Engine (regex.c) Crafted Socket Request DoS
47472Ruby dl Module DL.dlopen Arbitrary Library Access
47471WEBrick in Ruby WEBrick::HTTP::DefaultFileHandler Crafted HTTP Request DoS
47470Ruby Safe Level Multiple Function Restriction Bypass
47469Ruby resolv.rb DNS Query ID Field Prediction Cache Poisoning
Hide | Show 2 More...
idDescription
44682WEBrick in Ruby URI Multiple Encoded Traversal Arbitrary File Access
40773Ruby Multiple Net Modules Certificate commonName (CN) Field Verification Weak...

Milw0rm Exploits

idDescription
2008-08-13Ruby <= 1.9 (regex engine) Remote Socket Memory Leak Exploit

Metasploit Exploits

idDescription
2008-08-08Ruby WEBrick::HTTP::DefaultFileHandler DoS