Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2010-3299 The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. Rails No fix yet Fix from $1,6002019-11-12 HIGH 7.5 CVE-2016-6317 Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component … Rails Mitigation only Fix from $1,9502016-09-07 MEDIUM 6.1 CVE-2016-6316 Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow … Rails Mitigation only Fix from $1,6002016-09-07 HIGH 7.5 CVE-2015-7581EPSS 7% actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote att… Rails Mitigation only Fix from $1,9502016-02-16 MEDIUM 5.0 CVE-2015-3227 The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, a… Rails Mitigation only Fix from $1,6002015-07-26 MEDIUM 5.0 CVE-2014-7829 Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x bef… Rails No fix yet Fix from $1,6002014-11-18 MEDIUM 5.0 CVE-2014-3916 The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation faul… Rails Mitigation only Fix from $1,6002014-11-16 HIGH 7.5 CVE-2014-3514 activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote at… Rails Mitigation only Fix from $1,9502014-08-20 HIGH 7.5 CVE-2014-3482 SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record i… Rails Mitigation only Fix from $1,9502014-07-07 HIGH 7.5 CVE-2014-3483 SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record i… Rails Mitigation only Fix from $1,9502014-07-07 MEDIUM 6.8 CVE-2014-0080 SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4… Rails Mitigation only Fix from $1,6002014-02-20 MEDIUM 6.4 CVE-2013-3221 The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used … Rails No fix yet Fix from $1,6002013-04-22 MEDIUM 5.8 CVE-2013-1856 The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x befor… Rails Mitigation only Fix from $1,6002013-03-19 MEDIUM 5.0 CVE-2013-1854 The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by convertin… Rails Mitigation only Fix from $1,6002013-03-19 HIGH 7.5 CVE-2013-0333EPSS 95% lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML dat… Rails Mitigation only Fix from $1,9502013-01-30 MEDIUM 5.0 CVE-2012-3424 The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7… Rails Mitigation only Fix from $1,6002012-08-08 MEDIUM 6.4 CVE-2012-2660 actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider … Rails No fix yet Fix from $1,6002012-06-22 MEDIUM 5.0 CVE-2012-2661 The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing … Rails No fix yet Fix from $1,6002012-06-22 MEDIUM 6.4 CVE-2010-3933 Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the n… Rails Mitigation only Fix from $1,6002010-10-28 MEDIUM 6.8 CVE-2008-7248EPSS 8% Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers t… Rails No fix yet Fix from $1,6002009-12-16