ZeroHour

Vulnerabilities

42 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1979
A flaw has been found in mruby up to 3.4.0.

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415. It is advisable to implement a patch to correct this issue.

NVD description · AI analysis pending
1.9<1% PoC ×2
  • mruby mruby
CVE-2025-13120
A vulnerability has been found in mruby up to 3.4.0.

A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is eb398971bfb43c38db3e04528b68ac9a7ce509bc. It is advisable to implement a patch to correct this issue.

NVD description · AI analysis pending
1.9<1%
  • mruby mruby
CVE-2025-12875
A weakness has been identified in mruby 3.4.0.

A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing a manipulation of the argument start/length can lead to out-of-bounds write. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. This patch is called 93619f06dd378db6766666b30c08978311c7ec94. It is best practice to apply a patch to resolve this issue.

NVD description · AI analysis pending
1.9<1%
  • mruby mruby
CVE-2025-7207
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2.

A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 1fdd96104180cc0fb5d3cb086b05ab6458911bb9. It is recommended to apply a patch to fix this issue.

NVD description · AI analysis pending
1.9<1% PoC ×3
  • mruby mruby
CVE-2021-46023
An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc.

An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation fault and application crash.

NVD description · AI analysis pending
7.5<1% PoC
  • mruby mruby
CVE-2022-1934
Use After Free in GitHub repository mruby/mruby prior to 3.2.

Use After Free in GitHub repository mruby/mruby prior to 3.2.

NVD description · AI analysis pending
7.8<1% PoC
  • mruby mruby
CVE-2022-1427
Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2.

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

NVD description · AI analysis pending
7.8<1% PoC
  • mruby mruby
CVE-2022-1276
+1 in the same advisory: …1286
Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2.

Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

NVD description · AI analysis pending
9.82% PoC
  • mruby mruby
CVE-2022-1212
Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2.

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

NVD description · AI analysis pending
9.82% PoC
  • mruby mruby
CVE-2022-1201
NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2.

NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.

NVD description · AI analysis pending
6.5<1% PoC
  • mruby mruby
CVE-2022-1106
use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

NVD description · AI analysis pending
9.1<1% PoC
  • mruby mruby
CVE-2022-1071
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

NVD description · AI analysis pending
8.2<1% PoC
  • mruby mruby
CVE-2022-0890
NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.

NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.

NVD description · AI analysis pending
5.5<1% PoC
  • mruby mruby
CVE-2022-0717
Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

NVD description · AI analysis pending
9.1<1% PoC
  • mruby mruby
CVE-2022-0630
+1 in the same advisory: …0632
Out-of-bounds Read in Homebrew mruby prior to 3.2.

Out-of-bounds Read in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
7.1
group max
<1% PoC
  • mruby mruby
CVE-2022-0631
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
9.8<1% PoC
  • mruby mruby
CVE-2022-0623
Out-of-bounds Read in Homebrew mruby prior to 3.2.

Out-of-bounds Read in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
9.12% PoC
  • mruby mruby
CVE-2022-0614
Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.

Use of Out-of-range Pointer Offset in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
5.5<1% PoC
  • mruby mruby
CVE-2022-0570
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
9.81% PoC
  • mruby mruby
CVE-2022-0525
Out-of-bounds Read in Homebrew mruby prior to 3.2.

Out-of-bounds Read in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
9.11% PoC
  • mruby mruby
CVE-2022-0481
NULL Pointer Dereference in Homebrew mruby prior to 3.2.

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
7.5<1% PoC
  • mruby mruby
CVE-2022-0326
NULL Pointer Dereference in Homebrew mruby prior to 3.2.

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

NVD description · AI analysis pending
5.5<1% PoC
  • mruby mruby
CVE-2022-0240
mruby is vulnerable to NULL Pointer Dereference

mruby is vulnerable to NULL Pointer Dereference

NVD description · AI analysis pending
7.5<1% PoC
  • mruby mruby
CVE-2021-46020
An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.

An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.

NVD description · AI analysis pending
7.51% PoC
  • mruby mruby
CVE-2022-0080
mruby is vulnerable to Heap-based Buffer Overflow

mruby is vulnerable to Heap-based Buffer Overflow

NVD description · AI analysis pending
9.81% PoC
  • mruby mruby
CVE-2021-4188
mruby is vulnerable to NULL Pointer Dereference

mruby is vulnerable to NULL Pointer Dereference

NVD description · AI analysis pending
7.5<1% PoC
  • mruby mruby
CVE-2021-4110
mruby is vulnerable to NULL Pointer Dereference

mruby is vulnerable to NULL Pointer Dereference

NVD description · AI analysis pending
7.52% PoC
  • mruby mruby
CVE-2020-36401
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

NVD description · AI analysis pending
7.8<1% PoC
  • mruby mruby
CVE-2020-15866
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling.

mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.

NVD description · AI analysis pending
9.82% PoC
  • mruby mruby
  • mruby debian linux
CVE-2020-6840
+2 in the same advisory: …6838 …6839
In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.

In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.

NVD description · AI analysis pending
9.82% PoC
  • mruby mruby
CVE-2018-14337
The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access becaus

The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access because the mrb_str_resize function in string.c does not check for a negative length.

NVD description · AI analysis pending
7.51% PoC
  • mruby mruby
  • mruby debian linux
CVE-2018-12249
+2 in the same advisory: …12248 …12247
An issue was discovered in mruby 1.4.1.

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

NVD description · AI analysis pending
7.52% PoC
  • mruby mruby
  • mruby debian linux
CVE-2018-11743
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_ha

The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.

NVD description · AI analysis pending
9.82% PoC
  • mruby mruby
  • mruby debian linux
CVE-2018-10199
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy().

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

NVD description · AI analysis pending
9.82%
  • mruby mruby
CVE-2018-10191
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope ne

In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can use this to possibly execute arbitrary code.

NVD description · AI analysis pending
9.83% PoC
  • mruby mruby
  • mruby debian linux
CVE-2017-9527
The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) o

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.

NVD description · AI analysis pending
7.8<1% PoC
  • mruby mruby
  • mruby debian linux