Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。 Ruby中的String#unpack方法存在信息泄露漏洞,该漏洞源于程序没有正确的处理‘@’格式区分符。远程攻击者可通过发送请求,提交恶意输入利用该漏洞访问敏感信息。以下版本受到影响:Ruby 2.2.10之前的版本,2.3.7之前的2.3.x版本,2.4.4之前的2.4.x版本,2.5.1之前的2.5.x版本,2.6.0-preview1版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-4129 | 多款Apple产品WebKit 安全漏洞 | |
| CVE-2018-4148 | Apple iOS Telephony 缓冲区错误漏洞 | |
| CVE-2018-4146 | 多款Apple产品WebKit 安全漏洞 | |
| CVE-2018-4144 | 多款Apple产品Security 缓冲区错误漏洞 | |
| CVE-2018-4143 | 多款Apple产品Kernel 安全漏洞 | |
| CVE-2018-4142 | 多款Apple产品CoreText 安全漏洞 | |
| CVE-2018-4140 | Apple iOS Telephony 安全漏洞 | |
| CVE-2018-4139 | Apple macOS High Sierra kext tools 安全漏洞 | |
| CVE-2018-4138 | Apple macOS High Sierra NVIDIA Graphics Drivers 安全漏洞 | |
| CVE-2018-4137 | Apple Safar和iOS Safari Login AutoFill 安全漏洞 | |
| CVE-2018-4136 | Apple macOS High Sierra Kernel 安全漏洞 | |
| CVE-2018-4135 | Apple macOS High Sierra IOFireWireFamily 安全漏洞 | |
| CVE-2018-4134 | Apple iOS Safari 安全漏洞 | |
| CVE-2018-4133 | Apple Safari WebKit 跨站脚本漏洞 | |
| CVE-2018-4132 | Apple macOS High Sierra Intel Graphics Driver 安全漏洞 | |
| CVE-2018-4131 | Apple iOS和macOS High Sierra WindowServer 安全漏洞 | |
| CVE-2018-4130 | 多款Apple产品WebKit 安全漏洞 | |
| CVE-2018-4118 | 多款Apple产品WebKit 安全漏洞 | |
| CVE-2018-4116 | Apple Safari 安全漏洞 | |
| CVE-2018-4117 | 多款Apple产品WebKit 安全漏洞 |
Showing top 20 of 134 CVEs. View all on vendor page → →
No comments yet