Jeremy Evans
19 exploits
Active since Jun 2021
bindata < 2.4.10 - Denial of Service via Slow Bit Class Creation
CVSS 3.7
Rack <2.2.14,3.0.16,3.1.14 - Info Disclosure
CVSS 7.5
Rack <2.2.14,3.0.16,3.1.14 - Info Disclosure
CVSS 7.5
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Preamble Buffering
CVSS 7.5
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Form Non-File Fields
CVSS 7.5
Rack < 2.2.19 - Denial of Service via Unbounded Multipart Header Parsing
CVSS 7.5
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Preamble Buffering
CVSS 7.5
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Form Non-File Fields
CVSS 7.5
Rack < 2.2.19 - Denial of Service via Unbounded Multipart Header Parsing
CVSS 7.5
Rack < 2.2.22 - Cross-Site Scripting via Directory Index File Basename
CVSS 5.4
Rack 3.1.0-3.1.5 - Denial of Service via HTTP Accept Header Parsing
CVSS 6.5
Rack <2.2.11, 3.0.12, 3.1.10 - Info Disclosure
CVSS 6.5
Rack < 2.2.14 - Unauthenticated Session Restoration via Race Condition in Rack::Session::Pool
CVSS 4.2
Rack <2.2.14,3.0.16,3.1.14 - Info Disclosure
CVSS 7.5
Rack < 2.2.18 - Denial of Service via Query Parameter Separator Bypass
CVSS 7.5
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Preamble Buffering
CVSS 7.5
Rack < 2.2.19 - Uncontrolled Resource Consumption via Multipart Form Non-File Fields
CVSS 7.5
Rack < 2.2.19 - Denial of Service via Unbounded Multipart Header Parsing
CVSS 7.5
Ruby WEBrick < 1.8.2 - HTTP Request Smuggling via Header Terminator Parsing
CVSS 5.9