Search CVE reports


Toggle filters

131 – 140 of 150 results


CVE-2011-2929

Medium priority
Ignored

The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-2197

Medium priority
Ignored

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-0449

Low priority
Not affected

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-0448

Medium priority
Not affected

Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-0447

Medium priority

Some fixes available 3 of 6

Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2011-0446

Medium priority

Some fixes available 3 of 6

Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2010-3933

Medium priority
Not affected

Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2008-7248

Medium priority
Ignored

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2009-4214

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages

CVE-2009-3086

Low priority
Ignored

A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a...

1 affected package

rails

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
Show less packages