Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Rails MEDIUM 6.5
CVE-2010-3299

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

No fix yet
Fix from $1,600 2019-11-12
Rails HIGH 7.5
CVE-2016-6317

Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component …

Mitigation only
Fix from $1,950 2016-09-07
Rails MEDIUM 6.1
CVE-2016-6316

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow …

Mitigation only
Fix from $1,600 2016-09-07
Rails HIGH 7.5
CVE-2015-7581EPSS 7%

actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote att…

Mitigation only
Fix from $1,950 2016-02-16
Rails MEDIUM 5.0
CVE-2015-3227

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, a…

Mitigation only
Fix from $1,600 2015-07-26
Rails MEDIUM 5.0
CVE-2014-7829

Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x bef…

No fix yet
Fix from $1,600 2014-11-18
Rails MEDIUM 5.0
CVE-2014-3916

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation faul…

Mitigation only
Fix from $1,600 2014-11-16
Rails HIGH 7.5
CVE-2014-3514

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote at…

Mitigation only
Fix from $1,950 2014-08-20
Rails HIGH 7.5
CVE-2014-3482

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record i…

Mitigation only
Fix from $1,950 2014-07-07
Rails HIGH 7.5
CVE-2014-3483

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record i…

Mitigation only
Fix from $1,950 2014-07-07
Rails MEDIUM 6.8
CVE-2014-0080

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4…

Mitigation only
Fix from $1,600 2014-02-20
Rails MEDIUM 6.4
CVE-2013-3221

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used …

No fix yet
Fix from $1,600 2013-04-22
Rails MEDIUM 5.8
CVE-2013-1856

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x befor…

Mitigation only
Fix from $1,600 2013-03-19
Rails MEDIUM 5.0
CVE-2013-1854

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by convertin…

Mitigation only
Fix from $1,600 2013-03-19
Rails HIGH 7.5
CVE-2013-0333EPSS 95%

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML dat…

Mitigation only
Fix from $1,950 2013-01-30
Rails MEDIUM 5.0
CVE-2012-3424

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7…

Mitigation only
Fix from $1,600 2012-08-08
Rails MEDIUM 6.4
CVE-2012-2660

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider …

No fix yet
Fix from $1,600 2012-06-22
Rails MEDIUM 5.0
CVE-2012-2661

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing …

No fix yet
Fix from $1,600 2012-06-22
Rails MEDIUM 6.4
CVE-2010-3933

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the n…

Mitigation only
Fix from $1,600 2010-10-28
Rails MEDIUM 6.8
CVE-2008-7248EPSS 8%

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers t…

No fix yet
Fix from $1,600 2009-12-16