VDB

CVE-2015-9097

CVE-2015-9097 REJECTED

The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.

EPSS 3.36% · 87.6th percentile

Risk Scores

EPSS Score
3.36%
87.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSruby-mail0, *

Timeline

  • Jun 12, 2017 CVE Published
  • Jul 5, 2017 CVE Updated
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›