CVE-2014-7818
- EPSS 0.22%
- Veröffentlicht 08.11.2014 11:55:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, al...
CVE-2014-3514
- EPSS 0.33%
- Veröffentlicht 20.08.2014 11:17:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that...
CVE-2014-3482
- EPSS 1.53%
- Veröffentlicht 07.07.2014 11:01:30
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands b...
CVE-2014-3483
- EPSS 0.92%
- Veröffentlicht 07.07.2014 11:01:30
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary ...
CVE-2014-0130
- EPSS 52.71%
- Veröffentlicht 07.05.2014 10:55:04
- Zuletzt bearbeitet 21.04.2026 20:07:36
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, ...
CVE-2014-0081
- EPSS 0.89%
- Veröffentlicht 20.02.2014 15:27:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML ...
- EPSS 6.46%
- Veröffentlicht 20.02.2014 15:27:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memor...
CVE-2014-0080
- EPSS 0.25%
- Veröffentlicht 20.02.2014 15:27:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL com...
CVE-2013-4491
- EPSS 0.71%
- Veröffentlicht 07.12.2013 00:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script ...
- EPSS 70.84%
- Veröffentlicht 07.12.2013 00:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to e...