<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:43:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-04231</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-04231</link>
      <description>bdu:2019-04231</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-04231</guid>
    </item>
    <item>
      <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</link>
      <description>certfr-2022-avi-267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</guid>
    </item>
    <item>
      <title>cnvd-2018-07055</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-07055</link>
      <description>cnvd-2018-07055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-07055</guid>
    </item>
    <item>
      <title>EUVD-2026-71069</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-71069</link>
      <description>EUVD-2026-71069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-71069</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1000079</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000079</link>
      <description>&lt;p&gt;RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000079</guid>
    </item>
    <item>
      <title>GHSA-8qxg-mff5-j3wc — RubyGems Path Traversal vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8qxg-mff5-j3wc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rubygems-update, Maven: org.jruby:jruby-stdlib&lt;/p&gt;
&lt;p&gt;RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem writing to arbitrary filesystem locations during installation. This attack appears to be exploitable via installation of a malicious gem. This vulnerability is fixed in 2.7.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rubygems-update, Maven: org.jruby:jruby-stdlib&lt;/p&gt;
&lt;p&gt;RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem writing to arbitrary filesystem locations during installation. This attack appears to be exploitable via installation of a malicious gem. This vulnerability is fixed in 2.7.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8qxg-mff5-j3wc</guid>
    </item>
    <item>
      <title>gsd-2018-1000079</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1000079</link>
      <description>gsd-2018-1000079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1000079</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1771-1 — Security update for ruby-bundled-gems-rpmhelper, ruby2.5</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1771-1</link>
      <description>&lt;p&gt;Security update for ruby-bundled-gems-rpmhelper, ruby2.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby-bundled-gems-rpmhelper, ruby2.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1771-1</guid>
    </item>
    <item>
      <title>RHSA-2018:3729 — Red Hat Security Advisory: rh-ruby23-ruby security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:3729</link>
      <description>&lt;p&gt;ruby: HTTP response splitting in WEBrick ruby: Unintentional file and directory creation with directory traversal in tempfile and tmpdir ruby: DoS by large request in WEBrick ruby: Buffer under-read in String#unpack ruby: Unintentional socket creation by poisoned NULL byte in UNIXServer and UNIXSocket ruby: Unintentional directory traversal by poisoned NULL byte in Dir ruby: OpenSSL::X509:: Name equality check does not work correctly ruby: Tainted flags are not propagated in Array#pack and String#unpack with some directives rubygems: Path traversal when writing to a symlinked basedir outside of the root rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML rubygems: Infinite loop vulnerability due to negative size in tar header causes Denial of Service rubygems: Improper verification of signatures in tarball allows to install mis-signed gem rubygems: Missing URL validation on spec home attribute allows malicious gem to set an invalid homepage URL rubygems: XSS vulnerability in homepage attribute when displayed via gem server rubygems: Path traversal issue during gem installation allows to write to arbitrary filesystem locations&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby: HTTP response splitting in WEBrick ruby: Unintentional file and directory creation with directory traversal in tempfile and tmpdir ruby: DoS by large request in WEBrick ruby: Buffer under-read in String#unpack ruby: Unintentional socket creation by poisoned NULL byte in UNIXServer and UNIXSocket ruby: Unintentional directory traversal by poisoned NULL byte in Dir ruby: OpenSSL::X509:: Name equality check does not work correctly ruby: Tainted flags are not propagated in Array#pack and String#unpack with some directives rubygems: Path traversal when writing to a symlinked basedir outside of the root rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML rubygems: Infinite loop vulnerability due to negative size in tar header causes Denial of Service rubygems: Improper verification of signatures in tarball allows to install mis-signed gem rubygems: Missing URL validation on spec home attribute allows malicious gem to set an invalid homepage URL rubygems: XSS vulnerability in homepage attribute when displayed via gem server rubygems: Path traversal issue during gem installation allows to write to arbitrary filesystem locations&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:3729</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:1804-1 — Security update for ruby-bundled-gems-rpmhelper, ruby2.5</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:1804-1</link>
      <description>&lt;p&gt;Security update for ruby-bundled-gems-rpmhelper, ruby2.5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby-bundled-gems-rpmhelper, ruby2.5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:1804-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1000079</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000079</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby2.0, Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:18.04:LTS: jruby&lt;/p&gt;
&lt;p&gt;RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby2.0, Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:18.04:LTS: jruby&lt;/p&gt;
&lt;p&gt;RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000079</guid>
    </item>
  </channel>
</rss>
