← Back

Rubyforge

rubyforge

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Rubygems
rubygems

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Novell
Rubyforge
2Rubygem Sqlite3
Suse Linux Enterprise
Apr 29, 2026
May 13, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
1Rubyforge
1Rubygems
Apr 23, 2026
Jan 24, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of...Show more
The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.Show less