<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:34:43.932387+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-braid-cve-2013-0269</id>
    <title>BREW-braid-CVE-2013-0269 — JSON gem has Improper Input Validation vulnerability</title>
    <updated>2026-10-03T02:34:44.106969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: braid</p>
<p>The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-braid-cve-2013-0269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2013-avi-133</id>
    <title>certa-2013-avi-133 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby on Rails&lt;/span&gt; . Elles permettent à un at…</title>
    <updated>2026-10-03T02:34:44.107029+00:00</updated>
    <content>certa-2013-avi-133</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2013-avi-133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-104562</id>
    <title>EUVD-2026-104562</title>
    <updated>2026-10-03T02:34:44.107050+00:00</updated>
    <content>EUVD-2026-104562</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-104562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-0269</id>
    <title>fkie_cve-2013-0269</title>
    <updated>2026-10-03T02:34:44.107064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-0269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x457-cw4h-hq5f</id>
    <title>GHSA-x457-cw4h-hq5f — JSON gem has Improper Input Validation vulnerability</title>
    <updated>2026-10-03T02:34:44.107087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: json</p>
<p>The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x457-cw4h-hq5f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-0269</id>
    <title>gsd-2013-0269</title>
    <updated>2026-10-03T02:34:44.107112+00:00</updated>
    <content>gsd-2013-0269</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-0269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0686</id>
    <title>RHSA-2013:0686 — Red Hat Security Advisory: Subscription Asset Manager 1.2.1 update</title>
    <updated>2026-10-03T02:34:44.107124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Candlepin: bootstrap RPM deploys CA certificate file with mode 666 Candlepin: Re-enable manifest signature checking rubygem-rdoc: Cross-site scripting in the documentation created by Darkfish Rdoc HTML generator / template rubygem-rack: Timing attack in cookie sessions rubygem-json: Denial of Service and SQL Injection rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected Katello: Notifications page Username XSS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0269</id>
    <title>Withdrawn: UBUNTU-CVE-2013-0269</title>
    <updated>2026-10-03T02:34:44.107151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby-json</p>
<p>The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1601</id>
    <title>WID-SEC-W-2023-1601 — Red Hat JBoss Enterprise SOA Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:34:44.107171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise SOA Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen zu manipulieren oder um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1601"/>
  </entry>
</feed>
