Search CVE reports


Toggle filters

61 – 70 of 79 results


CVE-2014-7829

Low priority
Ignored

Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when...

11 affected packages

rails, rails-3.2, rails-4.0, ruby-actionpack-2.3, ruby-actionpack-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
rails-3.2 Not in release
rails-4.0 Not in release
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 11 packages Show less packages

CVE-2014-7818

Low priority
Ignored

Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when...

11 affected packages

rails, rails-3.2, rails-4.0, ruby-actionpack-2.3, ruby-actionpack-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
rails-3.2 Not in release
rails-4.0 Not in release
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 11 packages Show less packages

CVE-2014-3514

Medium priority
Ignored

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to...

11 affected packages

rails, rails-3.2, rails-4.0, ruby-actionpack-2.3, ruby-actionpack-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
rails-3.2
rails-4.0
ruby-actionpack-2.3
ruby-actionpack-3.2
ruby-activerecord-2.3
ruby-activerecord-3.2
ruby-activesupport-2.3
ruby-activesupport-3.2
ruby-rails-2.3
ruby-rails-3.2
Show all 11 packages Show less packages

CVE-2014-0082

Medium priority
Ignored

actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause...

4 affected packages

rails, rails-4.0, ruby-actionpack-2.3, ruby-actionpack-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
rails-4.0 Not in release
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
Show less packages

CVE-2014-0081

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary...

4 affected packages

rails, rails-4.0, ruby-actionpack-2.3, ruby-actionpack-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
rails-4.0 Not in release
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
Show less packages

CVE-2013-6417

Medium priority
Ignored

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages

CVE-2013-6416

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails
ruby-actionpack-2.3
ruby-actionpack-3.2
ruby-activerecord-2.3
ruby-activerecord-3.2
ruby-activesupport-2.3
ruby-activesupport-3.2
ruby-rails-2.3
ruby-rails-3.2
Show all 9 packages Show less packages

CVE-2013-6415

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web...

9 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-2.3, ruby-activerecord-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-2.3 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-2.3 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 9 packages Show less packages

CVE-2013-6414

Medium priority
Ignored

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME...

7 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2, ruby-activerecord-3.2, ruby-activesupport-3.2...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
ruby-activerecord-3.2 Not in release
ruby-activesupport-3.2 Not in release
ruby-rails-2.3 Not in release
ruby-rails-3.2 Not in release
Show all 7 packages Show less packages

CVE-2013-4491

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject...

3 affected packages

rails, ruby-actionpack-2.3, ruby-actionpack-3.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rails Not affected
ruby-actionpack-2.3 Not in release
ruby-actionpack-3.2 Not in release
Show less packages