Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rack HIGH 7.5
CVE-2024-26141

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Respo…

Fix: 2.2.8.1 / 3.0.9.1+
Fix from $1,950 2024-02-29
Rack HIGH 7.5
CVE-2024-26146

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a p…

Fix: 2.0.9.4 / 2.1.4.4+
Fix from $1,950 2024-02-29
Rack HIGH 7.5
CVE-2023-27530

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an at…

Fix: 2.0.9.3 / 2.1.4.3+
Fix from $1,950 2023-03-10
Rack HIGH 7.5
CVE-2022-44570

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsin…

Fix: 2.0.9.2 / 2.1.4.2+
Fix from $1,950 2023-02-09
Rack HIGH 7.5
CVE-2022-44571

There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This coul…

Fix: 2.0.9.2 / 2.1.4.2+
Fix from $1,950 2023-02-09
Rack HIGH 7.5
CVE-2022-44572

A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker t…

Fix: 2.0.9.2 / 2.1.4.2+
Fix from $1,950 2023-02-09
Rack MEDIUM 5.9
CVE-2019-16782

There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8…

Fix: 1.6.12 / 2.0.8+
Fix from $1,600 2019-12-18