Back to Database
Status published
Medium
CVE-2014-9490
The numtok function in lib/raven/okjson.rb in the raven-ruby gem before...
Vulnerability Description
The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9490
Credits & Attribution
No credits recorded in the NVD database.
References
More from getsentry
View All →CVE-2025-65944
Sentry-Javascript deals with leaked sensitive headers when `sendDefaultPii` is set to `true`
Medium
5.1
CVE-2025-53099
Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocation
Medium
5.5
CVE-2025-22146
Improper authentication on SAML SSO process allows user impersonation in sentry
Critical
9.1
CVE-2024-53253
Sentry's improper error handling leaks Application Integration Client Secret
Medium
5.3
CVE-2024-45606
Improper authorization on muting of alert rules in sentry
High
7.1
Affected Vendor
getsentry
View all reports →Affected Software
raven-ruby
Vulnerable Versions:
0
Timeline
Official Publish:
January 20th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.