Search CVE reports


Toggle filters

101 – 110 of 150 results


CVE-2013-6416

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-actionpack-2.3
ruby-actionpack-3.2
ruby-activerecord-2.3
ruby-activerecord-3.2
ruby-activesupport-2.3
ruby-activesupport-3.2
ruby-rails-2.3
ruby-rails-3.2
Show all 9 packages Show less packages

CVE-2013-6415

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages

CVE-2013-6414

Medium priority
Ignored

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME...

7 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-3.2, ruby-activesupport-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 7 packages Show less packages

CVE-2013-4491

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject...

3 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
Show less packages

CVE-2013-4389

Medium priority
Ignored

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address...

12 affected packages

rails, rails-4.0, ruby-actionmailer-2.3, ruby-actionmailer-3.2, ruby-actionpack-2.3...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
rails-4.0
ruby-actionmailer-2.3
ruby-actionmailer-3.2
ruby-actionpack-2.3
ruby-actionpack-3.2
ruby-activerecord-2.3
ruby-activerecord-3.2
ruby-activesupport-2.3
ruby-activesupport-3.2
ruby-rails-2.3
ruby-rails-3.2
Show all 12 packages Show less packages

CVE-2013-0285

Medium priority
Ignored

The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code,...

3 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-actionpack-2.3
ruby-actionpack-3.2
Show less packages

CVE-2013-1857

Medium priority

Some fixes available 1 of 35

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages

CVE-2013-1856

Medium priority

Some fixes available 1 of 30

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages

CVE-2013-1855

Medium priority

Some fixes available 1 of 35

The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n...

9 affected packages

ruby-activerecord-3.2, rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-activerecord-3.2 Not in release
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages

CVE-2013-1854

Medium priority

Some fixes available 1 of 35

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages