Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Passenger HIGH 7.5
CVE-2025-26803

The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP …

Fix: 6.0.26+
Fix from $1,950 2025-02-24
Passenger HIGH 7.5
CVE-2012-6135

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

Patch available
Fix from $1,950 2019-11-19
Passenger MEDIUM 5.3
CVE-2018-12615

An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not …

Fix: 5.3.2+
Fix from $1,600 2018-06-21
Passenger CRITICAL 9.8
CVE-2018-12026

During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to rep…

Fix: 5.3.2+
Fix from $2,300 2018-06-17
Passenger HIGH 8.8
CVE-2018-12027

An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation…

Fix: 5.3.2+
Fix from $1,950 2018-06-17
Passenger HIGH 7.8
CVE-2018-12028

An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, up…

Fix: 5.3.2+
Fix from $1,950 2018-06-17
Passenger HIGH 7.8
CVE-2016-10345

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers …

Fix: after 5.0.30
Fix from $1,950 2017-04-18
Juvia HIGH 7.5
CVE-2013-7134

Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/co…

Mitigation only
Fix from $1,950 2014-04-29