Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2020-22336
Disclosure Date: July 06, 2023 (last updated October 08, 2023)
An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.
0
Attacker Value
Unknown
CVE-2022-30123
Disclosure Date: December 05, 2022 (last updated November 18, 2023)
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
0
Attacker Value
Unknown
CVE-2022-30122
Disclosure Date: December 05, 2022 (last updated December 20, 2023)
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.
0
Attacker Value
Unknown
CVE-2022-37164
Disclosure Date: September 08, 2022 (last updated October 08, 2023)
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.
0
Attacker Value
Unknown
CVE-2020-8161
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
0
Attacker Value
Unknown
CVE-2020-8184
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
0
Attacker Value
Unknown
CVE-2019-18978
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
0
Attacker Value
Unknown
CVE-2018-16470
Disclosure Date: November 13, 2018 (last updated November 08, 2023)
There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.
0
Attacker Value
Unknown
CVE-2018-16471
Disclosure Date: November 13, 2018 (last updated November 08, 2023)
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.
0
Attacker Value
Unknown
CVE-2017-11655
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
A memory leak was found in the way SIPcrack 0.2 handled processing of SIP traffic, because a lines array was mismanaged. A remote attacker could potentially use this flaw to crash long-running sipdump network sniffing sessions.
0