rubygems

954 tracked vulnerabilities.

CVE-2013-1857
Redhat Enterprise Linux < 2.3.17 - XSS
Mar 19, 2013
EPSS 0.01
CVE-2013-1856
Ruby on Rails 3.0.x-3.1.x < 3.1.12 and 3.2.x < 3.2.13 - XML External Entity Injection via ActiveSupport::XmlMini_JDOM
Mar 19, 2013
EPSS 0.01
CVE-2013-1855
Ruby on Rails < 2.3.18, 3.0.x-3.1.x < 3.1.12, 3.2.x < 3.2.13 - Cross-Site Scripting via CSS Token Sequence
Mar 19, 2013
EPSS 0.01
CVE-2013-1854
Ruby on Rails 2.3.x < 2.3.18, 3.1.x < 3.1.12, 3.2.x < 3.2.13 - Denial of Service via Active Record Query Processing
Mar 19, 2013
EPSS 0.02
CVE-2013-2506
Spree <1.1.6, 1.2.x, 1.3.x - Privilege Escalation
Mar 08, 2013
EPSS 0.00
CVE-2013-1656
Spree Commerce 1.0.0-1.3.2 - Authenticated Remote Code Execution via Unsafe Constantize Function
Mar 08, 2013
EPSS 0.00
CVE-2013-0256
RDoc 2.3.0-3.12 and 4.x < 4.0.0.preview2.1 - Cross-Site Scripting via darkfish.js
Mar 01, 2013
EPSS 0.03
CVE-2013-0184
Rack 1.1.x-1.1.4, 1.2.x-1.2.6, 1.3.x-1.3.8, 1.4.x-1.4.3 - Denial of Service via Symbolized Arbitrary Strings
Mar 01, 2013
EPSS 0.01
CVE-2013-0183
Rack 1.3.0-1.3.7 and 1.4.0-1.4.2 - Denial of Service via Long String in Multipart HTTP Packet
Mar 01, 2013
EPSS 0.02
CVE-2013-0162
ruby_parser < 3.1.1 - Arbitrary File Write via Symlink Attack on Temporary File
Mar 01, 2013
EPSS 0.00
CVE-2013-0277
Ruby on Rails < 2.3.17 and 3.x < 3.1.0 - Remote Code Execution via YAML Deserialization
Feb 13, 2013
EPSS 0.07
CVE-2013-0276
Ruby on Rails < 2.3.17, 3.1.x < 3.1.11, 3.2.x < 3.2.12 - Unauthenticated Protected Attribute Bypass via Crafted Request
Feb 13, 2013
EPSS 0.01
CVE-2013-0269
JSON gem < 1.5.5, 1.6.x < 1.6.8, 1.7.x < 1.7.7 - DoS and Mass Assignment Bypass via Crafted JSON
Feb 13, 2013
EPSS 0.15
CVE-2013-0263
Rack <1.5.2, <1.4.5, <1.3.10, <1.2.8, <1.1.6 - RCE
Feb 08, 2013
EPSS 0.16
CVE-2013-0262
Rack 1.4.x < 1.4.5 and 1.5.x < 1.5.2 - Path Traversal via PATH_INFO Environment Variable
Feb 08, 2013
EPSS 0.01
CVE-2013-0333
Ruby on Rails 2.3.x-2.3.15 and 3.0.x-3.0.19 - Remote Code Execution via YAML Deserialization
Jan 30, 2013
EPSS 0.92
CVE-2013-0156
Ruby on Rails JSON Processor YAML Deserialization Code Execution
Jan 13, 2013
EPSS 0.92
CVE-2013-0155
Ruby on Rails 3.0.x < 3.0.19, 3.1.x < 3.1.10, 3.2.x < 3.2.11 - SQL Query Manipulation via JSON Parameter Handling
Jan 13, 2013
EPSS 0.18
CVE-2012-6685 HIGH
Nokogiri < 1.5.4 - XML External Entity Injection
Feb 19, 2020
CVSS 7.5
EPSS 0.00
CVE-2012-6135 HIGH
RubyGems passenger 4.0.0 beta1-beta2 - Arbitrary File Deletion
Nov 19, 2019
CVSS 7.5
EPSS 0.01
CVE-2012-6708 MEDIUM
jQuery < 1.9.0 - Cross-Site Scripting via jQuery(strInput) Function
Jan 18, 2018
CVSS 6.1
EPSS 0.01
CVE-2012-6684
RedCloth < 4.2.9 - Cross-Site Scripting via JavaScript URI
Jan 08, 2015
EPSS 0.01
CVE-2012-6662
Redhat Enterprise Linux Desktop < 1.10.0 - XSS
Nov 24, 2014
EPSS 0.07
CVE-2012-2126
RubyGems < 1.8.23 - Man-in-the-Middle Attack via Unverified SSL Certificate
Oct 01, 2013
EPSS 0.00
CVE-2012-2125
RubyGems < 1.8.23 - HTTPS to HTTP Redirection
Oct 01, 2013
EPSS 0.01