Ruby是一种功能强大的面向对象的脚本语言。 Ruby 1.8.4 以及之前版本,1.8.5-p231 之前的1.8.5, 1.8.6-p230之前的 1.8.6,1.8.7-p22 之前的 1.8.7版本,1.9.0-2 之前的1.9.0 版本,其 rb_str_buf_append 函数存在多个整数溢出漏洞,允许攻击者通过上下文关联造成拒绝服务攻击或执行任意代码。 注意:作为 20080624,出现了多个与 Ruby 相关的 CVE 标识符不一致的情况。CVE描述应被视为权威,虽然它可能会发生变化。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-2427 | XnView产品TAAC文件解析栈溢出漏洞 | |
| CVE-2008-2663 | Ruby rb_ary_store 函数多个整数溢出漏洞 | |
| CVE-2008-2664 | Ruby rb_str_forma 函数多个整数溢出漏洞 | |
| CVE-2008-2725 | Ruby 多个整数溢出漏洞 | |
| CVE-2008-2726 | Ruby 多个整数溢出漏洞 | |
| CVE-2008-2832 | Full Revolution aspWebCalendar 'calendar_admin.asp' 无限制文件上传漏洞 | |
| CVE-2008-2833 | le.cms admin/upload.php 权限绕过漏洞 | |
| CVE-2008-2834 | Scientific Image DataBase 'projects.php' SQL注入漏洞 | |
| CVE-2008-2835 | IGSuite cgi-bin/igsuite 'formid' 参数SQL注入漏洞 | |
| CVE-2008-2836 | WebCalendar 'tools/send_reminders.php' 远程文件包含漏洞 | |
| CVE-2008-2837 | CMS-BRD 'index.php' SQL注入漏洞 | |
| CVE-2008-2838 | Traindepot index.php 目录遍历漏洞 | |
| CVE-2008-2839 | Traindepot 搜索模块跨站脚本攻击漏洞 | |
| CVE-2008-2840 | Exero CMS 多个目录遍历漏洞 | |
| CVE-2008-2841 | xchat 代码注入漏洞 |
No comments yet