Dragonfly represents a narrowly scoped vendor footprint centered on its core product offering. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dragonfly over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33564CRITICAL An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url op | May 29, 2021 | 9.8 | 79 | NO | YES |
CVE-2021-33473CRITICAL An argument injection vulnerability in Dragonfly Ruby Gem v1.3.0 allows attackers to read and write arbitrary files when the verify_url option is disabled. This vulnerability is ex | Jun 2, 2022 | 9.1 | 30 | NO | NO |
CVE-2005-4351MEDIUM The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dragonfly.
Media articles that mention a CVE ID that affects a product developed by Dragonfly — matched by CVE ID, not by vendor name.