CVE Database
/

CVE-2016-2336

Back to search

CVE-2016-2336

Published: Jan 6, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.

VendorProductVersions

Ruby

Ruby

affected
2.3.0 dev
affected
2.2.2

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now