Back to Database
Status published
Medium
CVE-2014-3916
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and...
Vulnerability Description
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3916
Credits & Attribution
No credits recorded in the NVD database.
References
More from rubyonrails
View All →CVE-2025-54314
Thor before 1.4.0 can construct an unsafe shell command from...
Low
2.8
CVE-2019-25025
The activerecord-session_store (aka Active Record Session Store) component through 1.1.3...
Medium
5.3
CVE-2017-17920
SQL injection vulnerability in the 'reorder' method in Ruby on...
High
8.1
CVE-2017-17919
SQL injection vulnerability in the 'order' method in Ruby on...
Unknown
0
CVE-2017-17917
SQL injection vulnerability in the 'where' method in Ruby on...
High
8.1
Affected Vendor
rubyonrails
View all reports →Affected Software
rails
Vulnerable Versions:
1.9.3, 2.0.0, 2.1.0
Timeline
Official Publish:
November 16th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.