← Back

Mruby

mruby

42 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Mruby
mruby

CVEs (42)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mruby
1Mruby
Jun 17, 2026
Feb 6, 2026
1.9 LOW· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs...Show more
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415. It is advisable to implement a patch to correct this issue.Show less
1Mruby
1Mruby
Jun 17, 2026
Nov 13, 2025
1.9 LOW· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploi...Show more
A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is eb398971bfb43c38db3e04528b68ac9a7ce509bc. It is advisable to implement a patch to correct this issue.Show less
1Mruby
1Mruby
Jun 17, 2026
Nov 7, 2025
1.9 LOW· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/length can lead to out-...Show more
A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/length can lead to out-of-bounds write. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. This patch is called 93619f06dd378db6766666b30c08978311c7ec94. It is best practice to apply a patch to resolve this issue.Show less
1Mruby
1Mruby
Jun 17, 2026
Jul 9, 2025
1.9 LOW· v4
5.5 MEDIUM· v3
1.7 LOW· v2
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulat...Show more
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 1fdd96104180cc0fb5d3cb086b05ab6458911bb9. It is recommended to apply a patch to fix this issue.Show less
1Mruby
1Mruby
Jun 17, 2026
Feb 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash.
1Mruby
1Mruby
Jun 17, 2026
May 31, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Use After Free in GitHub repository mruby/mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Apr 23, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
1Mruby
1Mruby
Jun 17, 2026
Apr 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
1Mruby
1Mruby
Jun 17, 2026
Apr 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
1Mruby
1Mruby
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
1Mruby
1Mruby
Jun 17, 2026
Apr 2, 2022
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.
1Mruby
1Mruby
Jun 17, 2026
Mar 27, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Mar 26, 2022
N/A· v4
8.2 HIGH· v3
6.8 MEDIUM· v2
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Feb 23, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Feb 19, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Feb 19, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Out-of-bounds Read in Homebrew mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Feb 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Feb 17, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Out-of-bounds Read in Homebrew mruby prior to 3.2.
1Mruby
1Mruby
Jun 17, 2026
Feb 16, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.