Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-1904

23
FAUCET Score

CVE-2009-1904 describes a denial-of-service vulnerability in the BigDecimal library of Ruby versions 1.8.6 before p369 and 1.8.7 before p173. An attacker can crash an application by providing a large number as a string argument during an attempted conversion to a Float data type. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with a low attack complexity and potential for partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.8.6CPE matchmatch criteria
cpe:2.3:a:ruby-lang:ruby:1.8.6:*:*:*:*:*:*:*
1.8.7CPE matchmatch criteria
cpe:2.3:a:ruby-lang:ruby:1.8.7:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.63%
Probability of exploitation in next 30 days
EPSS Percentile
93.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0763 is in the 92nd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: ruby-0:1.8.1-7.el4_8.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: ruby-0:1.8.5-5.el5_3.7
View patch

Vendor Advisories (1)

redhatCVE-2009-1904Moderate

ruby: DoS vulnerability in BigDecimal

Jun 10, 2009

References

bugs.debian.org / cgi-bin/bugreport.cgi
Patch
bugs.gentoo.org / show_bug.cgi
github.com / NZKoz/bigdecimal-segfault-fix/tree/master
Patch
groups.google.com / group/rubyonrails-security/msg/fad60751e2b9b4f6
lists.apple.com / archives/security-announce/2010//Mar/msg00001.html
mail-index.netbsd.org / pkgsrc-changes/2009/06/10/msg024708.html
osvdb.org / 55031
redmine.ruby-lang.org / issues/show/794
ExploitPatch
bugs.launchpad.net / bugs/385436
bugs.launchpad.net / bugs/cve/2009-1904
secunia.com / advisories/35399
Vendor Advisory
secunia.com / advisories/35527
secunia.com / advisories/35593
secunia.com / advisories/35699
secunia.com / advisories/35937
secunia.com / advisories/37705
security.gentoo.org / glsa/glsa-200906-02.xml
exchange.xforce.ibmcloud.com / vulnerabilities/51032
slackware.com / security/viewer.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9780
support.apple.com / kb/HT4077
redhat.com / archives/fedora-package-announce/2009-December/msg00731.html
weblog.rubyonrails.org / 2009/6/10/dos-vulnerability-in-ruby
Patch
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2009-1140.html
ruby-forum.com / topic/189071
ruby-lang.org / en/news/2009/06/09/dos-vulnerability-in-bigdecimal
PatchVendor Advisory
securityfocus.com / bid/35278
securitytracker.com / id
ubuntu.com / usn/USN-805-1
vupen.com / english/advisories/2009/1563