Mike Dalessio
30 exploits
Active since Apr 2016
libxml2 < 2.9.3 - Heap-Based Buffer Overflow via Unclosed HTML Comment
Nokogiri 1.13.8-1.13.9 - Denial of Service via Unchecked Return Value in XML::Reader#attribute_hash
CVSS 7.5
Nokogiri <1.13.6 - Memory Corruption
CVSS 8.2
Rails::HTML::Sanitizer <1.16.8 - XSS
CVSS 6.1
Rails Action View Tag Helpers - Cross-Site Scripting
Active Storage <8.1.2.1, <8.0.4.1, <7.2.3.1 - Path Traversal
CVSS 9.8
Active Storage <8.1.2.1 - Path Traversal
CVSS 9.1
Rails Action View Tag Helpers - Cross-Site Scripting
Active Storage <8.1.2.1, <8.0.4.1, <7.2.3.1 - Path Traversal
CVSS 9.8
Active Storage <8.1.2.1 - Path Traversal
CVSS 9.1
Rails Action View Tag Helpers - Cross-Site Scripting
Active Storage <8.1.2.1, <8.0.4.1, <7.2.3.1 - Path Traversal
CVSS 9.8
Active Storage <8.1.2.1 - Path Traversal
CVSS 9.1
Nokogiri < 1.11.0 - XML External Entity Injection via Schema Parsing
CVSS 2.6
Mechanize <2.7.7 - Command Injection
CVSS 7.4
Nokogiri 1.13.8-1.13.9 - Denial of Service via Unchecked Return Value in XML::Reader#attribute_hash
CVSS 7.5
rails-html-sanitizer < 1.4.4 - Denial of Service via Inefficient SVG Attribute Regex
CVSS 7.5
Nokogiri < 1.13.4 - Inefficient Regular Expression Complexity in HTML Encoding Detection
CVSS 7.5
Nokogiri nekohtml < 1.9.22.noko2 - Denial of Service via Malformed HTML Markup
CVSS 7.5
Nokogiri <1.13.6 - Memory Corruption
CVSS 8.2
mechanize < 2.8.5 - Authorization Header Exposure via Redirect to Different Port
CVSS 5.9
Rails::HTML::Sanitizer <1.16.8 - XSS
CVSS 6.1
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via HTML5 Sanitization with Allowed math and style Elements
CVSS 6.1
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via Style Element Injection
CVSS 6.1
rails-html-sanitizer 1.6.0 - Cross-Site Scripting via Allowed Math and Style Elements
CVSS 6.1