<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:09:40 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</link>
      <description>certfr-2022-avi-267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</guid>
    </item>
    <item>
      <title>cnvd-2017-30057</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-30057</link>
      <description>cnvd-2017-30057</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-30057</guid>
    </item>
    <item>
      <title>EUVD-2026-184778</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-184778</link>
      <description>EUVD-2026-184778</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-184778</guid>
    </item>
    <item>
      <title>fkie_cve-2017-0903</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-0903</link>
      <description>&lt;p&gt;RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-0903</guid>
    </item>
    <item>
      <title>GHSA-mqwr-4qf2-2hcv — RubyGems vulnerable to Deserialization of Untrusted Data</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mqwr-4qf2-2hcv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rubygems-update&lt;/p&gt;
&lt;p&gt;RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. The issue has been patched in 2.6.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rubygems-update&lt;/p&gt;
&lt;p&gt;RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. The issue has been patched in 2.6.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mqwr-4qf2-2hcv</guid>
    </item>
    <item>
      <title>gsd-2017-0903</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-0903</link>
      <description>gsd-2017-0903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-0903</guid>
    </item>
    <item>
      <title>RHSA-2017:3485 — Red Hat Security Advisory: rh-ruby24-ruby security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:3485</link>
      <description>&lt;p&gt;ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the &amp;#34;summary&amp;#34; field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Arbitrary heap exposure during a JSON.generate call&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the &amp;#34;summary&amp;#34; field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Arbitrary heap exposure during a JSON.generate call&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:3485</guid>
    </item>
    <item>
      <title>RHSA-2018:0378 — Red Hat Security Advisory: ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:0378</link>
      <description>&lt;p&gt;ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the &amp;#34;summary&amp;#34; field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Buffer underrun in OpenSSL ASN1 decode ruby: Arbitrary heap exposure during a JSON.generate call ruby: Command injection vulnerability in Net::FTP ruby: Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code execution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby: Buffer underrun vulnerability in Kernel.sprintf rubygems: Escape sequence in the &amp;#34;summary&amp;#34; field of gemspec rubygems: No size limit in summary length of gem spec rubygems: Arbitrary file overwrite due to incorrect validation of specification name rubygems: DNS hijacking vulnerability rubygems: Unsafe object deserialization through YAML formatted gem specifications ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick ruby: Buffer underrun in OpenSSL ASN1 decode ruby: Arbitrary heap exposure during a JSON.generate call ruby: Command injection vulnerability in Net::FTP ruby: Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code execution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:0378</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1570-1 — Security update for ruby2.1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1570-1</link>
      <description>&lt;p&gt;Security update for ruby2.1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby2.1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1570-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-0903</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-0903</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby2.0, Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby&lt;/p&gt;
&lt;p&gt;RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby2.0, Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby&lt;/p&gt;
&lt;p&gt;RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-0903</guid>
    </item>
  </channel>
</rss>
