Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2014-1831

Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.
0
Attacker Value
Unknown

CVE-2013-7134

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.
0
Attacker Value
Unknown

CVE-2013-2119

Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
0
Attacker Value
Unknown

CVE-2013-4136

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.
0