Ruby FFI is a narrowly scoped library that bridges Ruby code with native C libraries through a foreign-function interface, presenting a small but critical component in the Ruby ecosystem's interoperability layer. The library's vulnerability profile reflects its role as a wrapper around low-level native calls, with the observed exposure tied to the complexity of marshaling data between runtime boundaries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ruby Ffi Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000201HIGH ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to | Jun 22, 2018 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ruby Ffi Project.
Media articles that mention a CVE ID that affects a product developed by Ruby Ffi Project — matched by CVE ID, not by vendor name.