检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-P692-7MM3-3FXG CVE-2015-7576 | actionpack is vulnerable to remote bypass authentication | 低危 | RubyGemsactionpack | 已审查 | 2017-10-25 02:33 | 2023-08-01 04:59 |
| GHSA-P65M-QR5X-RRQQ CVE-2013-7086 | Webbynode Code Injection vulnerability |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
RubyGemswebbynode |
| 已审查 |
| 2017-10-25 02:33 |
| 2023-01-27 05:22 |
| GHSA-MX9F-W8QQ-Q5JF CVE-2015-3448 | rest-client allows local users to obtain sensitive information by reading the log | 低危 | RubyGemsrest-client | 已审查 | 2017-10-25 02:33 | 2023-01-24 05:26 |
| GHSA-MHWP-QHPC-H3JM CVE-2014-3482 | SQL Injection in Active Record | 高危 | RubyGemsactiverecord | 已审查 | 2017-10-25 02:33 | 2025-04-01 01:07 |
| GHSA-M46P-GGM5-5J83 CVE-2014-0081 | Rails vulnerable to Cross-site Scripting | 中危 | RubyGemsactionpack+1 | 已审查 | 2017-10-25 02:33 | 2023-07-06 04:33 |
| GHSA-JJV7-QPX3-H62Q CVE-2014-7191 | Denial-of-Service Memory Exhaustion in qs | 高危 | npmqs | 已审查 | 2017-10-25 02:33 | 2021-09-15 03:46 |
| GHSA-JGQF-HWC5-HH37 CVE-2015-8859 | Root Path Disclosure in send | 中危 | npmsend | 已审查 | 2017-10-25 02:33 | 2021-09-15 03:42 |
| GHSA-J96R-XVJQ-R9PG CVE-2015-3227 | activesupport vulnerable to Denial of Service via large XML document depth | 中危 | RubyGemsactivesupport | 已审查 | 2017-10-25 02:33 | 2025-04-01 01:46 |
| GHSA-HQF9-RC9J-5FMJ CVE-2014-0080 | Array data injection vulnerability in activerecord | 中危 | RubyGemsactiverecord | 已审查 | 2017-10-25 02:33 | 2023-07-06 01:50 |
| GHSA-HJCP-J389-59FF CVE-2015-8854 | Regular Expression Denial of Service in marked | 高危 | npmmarked | 已审查 | 2017-10-25 02:33 | 2024-02-10 01:50 |
| GHSA-HGMW-X865-HF9X CVE-2014-2322 | Arabic Prawn allows remote attackers to execute arbitrary commands via shell metacharacters | 高危 | RubyGemsArabic-Prawn | 已审查 | 2017-10-25 02:33 | 2023-01-27 04:58 |
| GHSA-H56M-VWXC-3QPW CVE-2014-7829 | Directory traversal vulnerability in actionpack | 中危 | RubyGemsactionpack | 已审查 | 2017-10-25 02:33 | 2023-08-26 03:56 |
| GHSA-GHQM-PGXJ-37GQ CVE-2015-7580 | rails-html-sanitizer Cross-site Scripting vulnerability | 中危 | RubyGemsrails-html-sanitizer | 已审查 | 2017-10-25 02:33 | 2023-01-24 05:16 |
| GHSA-GFJR-3JMM-4G9V CVE-2015-8860 | Symlink Arbitrary File Overwrite in tar | 高危 | npmtar | 已审查 | 2017-10-25 02:33 | 2021-09-11 04:53 |
| GHSA-FQRR-RRWG-69PV CVE-2014-1233 | Local API Login Credentials Disclosure in paratrooper-pingdom | 低危 | RubyGemsparatrooper-pingdom | 已审查 | 2017-10-25 02:33 | 2023-07-06 02:46 |
| GHSA-FMR4-7G9Q-7HC7 | Moderate severity vulnerability that affects handlebars 已撤回 | 中危 | npmhandlebars | 已审查 | 2017-10-25 02:33 | 2020-06-18 00:30 |
| GHSA-CQR7-78PJ-3G7J CVE-2014-3742 | File Descriptor Leak Can Cause DoS Vulnerability in hapi | 高危 | npmhapi | 已审查 | 2017-10-25 02:33 | 2021-09-10 04:31 |
| GHSA-CFJH-P3G4-3Q2F CVE-2015-1370 | VBScript Content Injection in marked | 中危 | npmmarked | 已审查 | 2017-10-25 02:33 | 2021-09-10 01:02 |
| GHSA-C9F4-XJ24-8JQX CVE-2015-8858 | Regular Expression Denial of Service in uglify-js | 高危 | npmuglify-js | 已审查 | 2017-10-25 02:33 | 2021-09-09 05:59 |
| GHSA-C9C5-9FPR-M882 CVE-2014-9490 | sentry-raven allows remote attackers to cause a denial of service via a large exponent value in a scientific number | 中危 | RubyGemssentry-raven | 已审查 | 2017-10-25 02:33 | 2023-01-26 07:16 |
| GHSA-9RF5-JM6F-2FMM CVE-2014-3514 | Active Record subject to strong parameters protection bypass | 高危 | RubyGemsactiverecord | 已审查 | 2017-10-25 02:33 | 2023-08-26 06:56 |
| GHSA-9H6G-GP95-X3Q5 CVE-2015-7581 | actionpack is vulnerable to denial of service because of a wildcard controller route | 高危 | RubyGemsactionpack | 已审查 | 2017-10-25 02:33 | 2022-04-26 04:52 |
| GHSA-9959-C6Q6-6QP3 | Moderate severity vulnerability that affects validator 已撤回 | 中危 | npmvalidator | 已审查 | 2017-10-25 02:33 | 2020-06-18 00:30 |
| GHSA-959J-5G9V-3FPQ CVE-2014-1234 | Paratrooper-newrelic Exposes of Sensitive Information to an Unauthorized Actor | 低危 | RubyGemsparatrooper-newrelic | 已审查 | 2017-10-25 02:33 | 2023-08-26 06:59 |
| GHSA-92V7-PQ4H-58J5 CVE-2014-3248 | facter, hiera, mcollective-client, and puppet affected by untrusted search path vulnerability | 中危 | RubyGemsfacter+3 | 已审查 | 2017-10-25 02:33 | 2023-06-07 22:06 |