Vulnerability index

Browse CVEs

110 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rails HIGH 7.5
CVE-2012-6496

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote …

Fix: after 3.0.17
Fix from $1,950 2013-01-04
Rails MEDIUM 5.0
CVE-2012-6497

The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might all…

Fix: 3.2.10+
Fix from $1,600 2013-01-04
Rails MEDIUM 5.0
CVE-2012-3424

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7…

Mitigation only
Fix from $1,600 2012-08-08
Rails HIGH 7.5
CVE-2012-2695

The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of req…

Fix: after 3.0.13
Fix from $1,950 2012-06-22
Rails MEDIUM 6.4
CVE-2012-2660

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider …

No fix yet
Fix from $1,600 2012-06-22
Rails MEDIUM 5.0
CVE-2012-2661

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing …

No fix yet
Fix from $1,600 2012-06-22
Rails HIGH 7.5
CVE-2011-2930

Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapt…

Patch available
Fix from $1,950 2011-08-29
Rails MEDIUM 5.0
CVE-2011-2929

The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.r…

Patch available
Fix from $1,600 2011-08-29
Rails HIGH 7.5
CVE-2011-0448

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attack…

Patch available
Fix from $1,950 2011-02-21
Rails HIGH 7.5
CVE-2011-0449

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly im…

Patch available
Fix from $1,950 2011-02-21
Rails MEDIUM 6.8
CVE-2011-0447

Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With …

Patch available
Fix from $1,600 2011-02-14
Rails MEDIUM 6.4
CVE-2010-3933

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the n…

Mitigation only
Fix from $1,600 2010-10-28
Rails MEDIUM 6.8
CVE-2008-7248EPSS 8%

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers t…

No fix yet
Fix from $1,600 2009-12-16
Rails MEDIUM 5.0
CVE-2009-3086

A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature …

Patch available
Fix from $1,600 2009-09-08
Ruby On Rails CRITICAL 9.8
CVE-2009-2422

The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_reques…

Fix: 2.3.3 / 10.6.3+
Fix from $2,300 2009-07-10
Rails MEDIUM 5.0
CVE-2008-5189

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitti…

Fix: after 2.0.4
Fix from $1,600 2008-11-21
Rails HIGH 7.5
CVE-2008-4094

Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and …

Fix: after 2.1.0
Fix from $1,950 2008-09-30
Rails MEDIUM 6.8
CVE-2007-6077

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEF…

Patch available
Fix from $1,600 2007-11-21
Rails HIGH 7.5
CVE-2006-4111

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP head…

Fix: after 1.1.4
Fix from $1,950 2006-08-14
Rails HIGH 7.5
CVE-2006-4112

Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2006-08-14