<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:49:30.825864+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2016-00577</id>
    <title>bdu:2016-00577</title>
    <updated>2026-10-03T15:49:31.052832+00:00</updated>
    <content>bdu:2016-00577</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2016-00577"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2016-avi-037</id>
    <title>certfr-2016-avi-037 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby On Rails&lt;/span&gt;. Certaines d'entre elles p…</title>
    <updated>2026-10-03T15:49:31.052885+00:00</updated>
    <content>certfr-2016-avi-037</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2016-avi-037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-00968</id>
    <title>cnvd-2016-00968</title>
    <updated>2026-10-03T15:49:31.052925+00:00</updated>
    <content>cnvd-2016-00968</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-00968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256406</id>
    <title>EUVD-2026-256406</title>
    <updated>2026-10-03T15:49:31.052946+00:00</updated>
    <content>EUVD-2026-256406</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-0752</id>
    <title>fkie_cve-2016-0752</title>
    <updated>2026-10-03T15:49:31.052964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-0752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrr4-p6fq-hjg7</id>
    <title>GHSA-xrr4-p6fq-hjg7 — Directory traversal vulnerability in Action View in Ruby on Rails</title>
    <updated>2026-10-03T15:49:31.053016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: actionview, RubyGems: actionpack</p>
<p>Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a `..` (dot dot) in a pathname.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrr4-p6fq-hjg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-0752</id>
    <title>gsd-2016-0752</title>
    <updated>2026-10-03T15:49:31.053059+00:00</updated>
    <content>gsd-2016-0752</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-0752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2016:0296</id>
    <title>RHSA-2016:0296 — Red Hat Security Advisory: rh-ror41 security update</title>
    <updated>2026-10-03T15:49:31.053079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller rubygem-activerecord: Nested attributes rejection proc bypass in Active Record rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack rubygem-actionpack: possible object leak and denial of service attack in Action Pack rubygem-actionpack: directory traversal flaw in Action View rubygem-activerecord: possible input validation circumvention in Active Model</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2016:0296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:0456-1</id>
    <title>SUSE-SU-2016:0456-1 — Security update for rubygem-actionview-4_2</title>
    <updated>2026-10-03T15:49:31.053137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-actionview-4_2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:0456-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0752</id>
    <title>Withdrawn: UBUNTU-CVE-2016-0752</title>
    <updated>2026-10-03T15:49:31.053157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: rails</p>
<p>Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1085</id>
    <title>WID-SEC-W-2025-1085 — Ruby on Rails: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:49:31.053179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Sicherheitsfunktionen zu umgehen, um Dateien zu manipulieren oder um einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1085"/>
  </entry>
</feed>
