Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.5
CVE-2013-6460
- EPSS 2.08%
- Veröffentlicht 05.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:59:16
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
9.8
CVE-2019-5477
- EPSS 5.9%
- Veröffentlicht 16.08.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:45:00
A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being c...