Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-4164

Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point value, as demonstrated using (1) the to_f method or (2) JSON.parse.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.111
EPSS Ranking 93.2%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2013-4164
  • Ruby-Lang » Ruby » Version: 1.8
    cpe:2.3:a:ruby-lang:ruby:1.8
  • Ruby-Lang » Ruby » Version: 1.9
    cpe:2.3:a:ruby-lang:ruby:1.9
  • Ruby-Lang » Ruby » Version: 1.9.1
    cpe:2.3:a:ruby-lang:ruby:1.9.1
  • Ruby-Lang » Ruby » Version: 1.9.2
    cpe:2.3:a:ruby-lang:ruby:1.9.2
  • Ruby-Lang » Ruby » Version: 1.9.3
    cpe:2.3:a:ruby-lang:ruby:1.9.3
  • Ruby-Lang » Ruby » Version: 2.0.0
    cpe:2.3:a:ruby-lang:ruby:2.0.0
  • Ruby-Lang » Ruby » Version: 2.1
    cpe:2.3:a:ruby-lang:ruby:2.1


Contact Us

Shodan ® - All rights reserved