Show filters
348 Total Results
Displaying 81-90 of 348
Sort by:
Attacker Value
Unknown
CVE-2021-44528
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
0
Attacker Value
Unknown
CVE-2022-0080
Disclosure Date: January 02, 2022 (last updated February 23, 2025)
mruby is vulnerable to Heap-based Buffer Overflow
0
Attacker Value
Unknown
CVE-2021-41819
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
0
Attacker Value
Unknown
CVE-2021-41817
Disclosure Date: January 01, 2022 (last updated February 23, 2025)
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
0
Attacker Value
Unknown
CVE-2021-4188
Disclosure Date: December 30, 2021 (last updated February 23, 2025)
mruby is vulnerable to NULL Pointer Dereference
0
Attacker Value
Unknown
CVE-2021-4110
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
mruby is vulnerable to NULL Pointer Dereference
0
Attacker Value
Unknown
CVE-2011-1497
Disclosure Date: October 19, 2021 (last updated February 23, 2025)
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.
0
Attacker Value
Unknown
CVE-2021-22942
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
0
Attacker Value
Unknown
CVE-2021-28966
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
0
Attacker Value
Unknown
CVE-2021-36773
Disclosure Date: July 18, 2021 (last updated February 23, 2025)
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
0