<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:34:45 +0000</lastBuildDate>
    <item>
      <title>BREW-braid-CVE-2013-0269 — JSON gem has Improper Input Validation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/brew-braid-cve-2013-0269</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: braid&lt;/p&gt;
&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: braid&lt;/p&gt;
&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-braid-cve-2013-0269</guid>
    </item>
    <item>
      <title>certa-2013-avi-133 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby on Rails&lt;/span&gt; . Elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2013-avi-133</link>
      <description>certa-2013-avi-133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2013-avi-133</guid>
    </item>
    <item>
      <title>EUVD-2026-104562</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-104562</link>
      <description>EUVD-2026-104562</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-104562</guid>
    </item>
    <item>
      <title>fkie_cve-2013-0269</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-0269</link>
      <description>&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-0269</guid>
    </item>
    <item>
      <title>GHSA-x457-cw4h-hq5f — JSON gem has Improper Input Validation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x457-cw4h-hq5f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: json&lt;/p&gt;
&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: json&lt;/p&gt;
&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x457-cw4h-hq5f</guid>
    </item>
    <item>
      <title>gsd-2013-0269</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-0269</link>
      <description>gsd-2013-0269</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-0269</guid>
    </item>
    <item>
      <title>RHSA-2013:0686 — Red Hat Security Advisory: Subscription Asset Manager 1.2.1 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0686</link>
      <description>&lt;p&gt;Candlepin: bootstrap RPM deploys CA certificate file with mode 666 Candlepin: Re-enable manifest signature checking rubygem-rdoc: Cross-site scripting in the documentation created by Darkfish Rdoc HTML generator / template rubygem-rack: Timing attack in cookie sessions rubygem-json: Denial of Service and SQL Injection rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected Katello: Notifications page Username XSS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Candlepin: bootstrap RPM deploys CA certificate file with mode 666 Candlepin: Re-enable manifest signature checking rubygem-rdoc: Cross-site scripting in the documentation created by Darkfish Rdoc HTML generator / template rubygem-rack: Timing attack in cookie sessions rubygem-json: Denial of Service and SQL Injection rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected Katello: Notifications page Username XSS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0686</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2013-0269</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0269</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-json&lt;/p&gt;
&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-json&lt;/p&gt;
&lt;p&gt;The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka &amp;#34;Unsafe Object Creation Vulnerability.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0269</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1601 — Red Hat JBoss Enterprise SOA Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1601</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise SOA Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen zu manipulieren oder um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat JBoss Enterprise SOA Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen zu manipulieren oder um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1601</guid>
    </item>
  </channel>
</rss>
