<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:31:47.640503+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2017-02342</id>
    <title>bdu:2017-02342</title>
    <updated>2026-10-02T21:31:47.675077+00:00</updated>
    <content>bdu:2017-02342</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2017-02342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2017-10784</id>
    <title>Withdrawn: BELL-CVE-2017-10784 — CVE-2017-10784 does not affect BellSoft software</title>
    <updated>2026-10-02T21:31:47.675116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2017-10784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-serveit-cve-2017-10784</id>
    <title>BREW-serveit-CVE-2017-10784 — WEBrick RCE Vulnerability</title>
    <updated>2026-10-02T21:31:47.675135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: serveit</p>
<p>The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-serveit-cve-2017-10784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-524</id>
    <title>certfr-2018-avi-524 — De multiples vulnérabilités ont été découvertes dans les produits Apple.
Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-02T21:31:47.675165+00:00</updated>
    <content>certfr-2018-avi-524</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-mz31215</id>
    <title>CLEANSTART-2026-MZ31215 — Security fix for CVE-2017-10784 applied in: ruby 2.4.2-r0</title>
    <updated>2026-10-02T21:31:47.675181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby</p>
<p>Security vulnerability affects the ruby package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-mz31215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-34706</id>
    <title>cnvd-2017-34706</title>
    <updated>2026-10-02T21:31:47.675201+00:00</updated>
    <content>cnvd-2017-34706</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-34706"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-76346</id>
    <title>EUVD-2026-76346</title>
    <updated>2026-10-02T21:31:47.675228+00:00</updated>
    <content>EUVD-2026-76346</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-76346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-10784</id>
    <title>fkie_cve-2017-10784</title>
    <updated>2026-10-02T21:31:47.675240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-10784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-369m-2gv6-mw28</id>
    <title>GHSA-369m-2gv6-mw28 — WEBrick RCE Vulnerability</title>
    <updated>2026-10-02T21:31:47.675262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: webrick</p>
<p>The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-369m-2gv6-mw28"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-10784</id>
    <title>gsd-2017-10784</title>
    <updated>2026-10-02T21:31:47.675281+00:00</updated>
    <content>gsd-2017-10784</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-10784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:3485</id>
    <title>RHSA-2017:3485 — Red Hat Security Advisory: rh-ruby24-ruby security, bug fix, and enhancement update</title>
    <updated>2026-10-02T21:31:47.675292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the "summary" field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Arbitrary heap exposure during a JSON.generate call</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:3485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:0378</id>
    <title>RHSA-2018:0378 — Red Hat Security Advisory: ruby security update</title>
    <updated>2026-10-02T21:31:47.675326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the "summary" field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Buffer underrun in OpenSSL ASN1 decode ruby: Arbitrary heap exposure during a JSON.generate call ruby: Command injection vulnerability in Net::FTP ruby: Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:0378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:1570-1</id>
    <title>SUSE-SU-2020:1570-1 — Security update for ruby2.1</title>
    <updated>2026-10-02T21:31:47.675360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby2.1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:1570-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-10784</id>
    <title>UBUNTU-CVE-2017-10784</title>
    <updated>2026-10-02T21:31:47.675401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby1.9.1, Ubuntu:14.04:LTS: ruby2.0, Ubuntu:16.04:LTS: ruby2.3</p>
<p>The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-10784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1423</id>
    <title>WID-SEC-W-2026-1423 — Ruby: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:31:47.675423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, einen Denial of Service Angriff durchzuführen oder Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1423"/>
  </entry>
</feed>
