Search CVE reports


Toggle filters

121 – 130 of 150 results


CVE-2012-2661

Medium priority
Not affected

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote...

2 affected packages

rails, ruby-rails-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-rails-2.3
Show less packages

CVE-2012-2660

Low priority
Ignored

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the...

2 affected packages

rails, ruby-rails-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-rails-2.3
Show less packages

CVE-2012-1099

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to...

2 affected packages

rails, ruby-rails-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-rails-2.3
Show less packages

CVE-2012-1098

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object...

2 affected packages

ruby-rails-2.3, rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-rails-2.3
rails
Show less packages

CVE-2011-4319

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to...

2 affected packages

rails, ruby-actionpack-2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-actionpack-2.3
Show less packages

CVE-2011-3187

Low priority
Ignored

The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-3186

Medium priority

Some fixes available 3 of 4

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-2932

Medium priority

Some fixes available 3 of 4

Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-2931

Medium priority

Some fixes available 3 of 4

Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-2930

Medium priority

Some fixes available 3 of 4

Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages