Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 308 respecto a la semana anterior
Críticas / altas1351▲ 88 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.9% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 8/8/2012 | 16/6/2026 | The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7, and 3.2.x before 3.2.7 converts Digest Authentication strings to symbols, which allows remote attackers to cause a denial of service by leveraging access to an… | |
| Modificada | Alta (7.5) | 4.5% | — | Rubygems Mail GEM | 18/7/2012 | 16/6/2026 | The Mail gem before 2.4.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) sendmail or (2) exim delivery. | |
| Modificada | Media (5) | 4.9% | — | Rubygems Mail GEM | 18/7/2012 | 16/6/2026 | Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a .. (dot dot) in the to parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 22/6/2012 | 16/6/2026 | The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage… | |
| Modificada | Media (4.3) | 3.9% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 22/6/2012 | 16/6/2026 | actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions… | |
| Modificada | Media (5) | 4.1% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 22/6/2012 | 16/6/2026 | The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that… | |
| Modificada | Media (6.4) | 4.6% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 22/6/2012 | 16/6/2026 | actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions… | |
| Modificada | Alta (7.5) | 1.7% | — | Artonx.org Activescriptruby | 16/4/2012 | 16/6/2026 | GRScript18.dll before 1.2.2.0 in ActiveScriptRuby (ASR) before 1.8.7 does not properly restrict interaction with an Internet Explorer ActiveX environment, which allows remote attackers to execute arbitrary Ruby code via a crafted HTML document. | |
| Modificada | Media (4.3) | 2.5% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION… | |
| Modificada | Media (4.3) | 2.7% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 13/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods. | |
| Modificada | Media (5) | 4.2% | — | Jruby | 30/12/2011 | 16/6/2026 | JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. | |
| Modificada | Alta (7.8) | 4.1% | — | Ruby-lang Ruby | 30/12/2011 | 16/6/2026 | Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. | |
| Modificada | Media (4.3) | 1.6% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 28/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with… | |
| Modificada | Media (4.3) | 6.7% | — | Rubyonrails Rails | 29/8/2011 | 16/6/2026 | The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted… | |
| Modificada | Media (4.3) | 1.7% | — | Rubyonrails Rails | 29/8/2011 | 16/6/2026 | CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header. | |
| Modificada | Media (4.3) | 2.5% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 29/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails 2.x before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string, related to a "UTF-8 escaping… | |
| Modificada | Media (4.3) | 2.5% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 29/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name. | |
| Modificada | Alta (7.5) | 2.3% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 29/8/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name. | |
| Modificada | Media (5) | 1.8% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 29/8/2011 | 16/6/2026 | The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a "filter skipping vulnerability." | |
| Modificada | Media (5) | 2.0% | — | Ruby-lang Ruby | 5/8/2011 | 16/6/2026 | Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. | |
| Modificada | Media (5) | 2.2% | — | Ruby-lang Ruby | 5/8/2011 | 16/6/2026 | The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with… | |
| Modificada | Media (5) | 2.6% | — | Ruby-lang Ruby | 5/8/2011 | 16/6/2026 | Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. NOTE: this issue exists because of a… | |
| Modificada | Media (4.3) | 2.0% | — | Rubyonrails RailsRubyonrails Ruby ON Rails | 30/6/2011 | 16/6/2026 | The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string… | |
| Modificada | Baja (2.1) | 0.38% | — | Rubyforge Rubygem-sqlite3Novell Suse Linux Enterprise | 13/5/2011 | 16/6/2026 | The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. | |
| Modificada | Media (6.8) | 3.0% | — | Ruby-lang Ruby | 23/3/2011 | 16/6/2026 | The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors… |