NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28105 | CVE-2015-7577 | activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 28106 | CVE-2015-7578 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 28107 | CVE-2015-7579 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 28108 | CVE-2015-7580 | Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-05 | View | |
| 28109 | CVE-2015-7581 | actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application"s use of a wildcard controller route. | 2 | 5 | Medium | 2017-01-19 | 2016-12-05 | View |
Page 14948 of 17672, showing 5 records out of 88360 total, starting on record 74736, ending on 74740