<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:53:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2016-00577</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2016-00577</link>
      <description>bdu:2016-00577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2016-00577</guid>
    </item>
    <item>
      <title>certfr-2016-avi-037 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Ruby On Rails&lt;/span&gt;. Certaines d'entre elles p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2016-avi-037</link>
      <description>certfr-2016-avi-037</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2016-avi-037</guid>
    </item>
    <item>
      <title>cnvd-2016-00968</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-00968</link>
      <description>cnvd-2016-00968</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-00968</guid>
    </item>
    <item>
      <title>EUVD-2026-256406</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256406</link>
      <description>EUVD-2026-256406</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256406</guid>
    </item>
    <item>
      <title>fkie_cve-2016-0752</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-0752</link>
      <description>&lt;p&gt;Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application&amp;#39;s unrestricted use of the render method and providing a .. (dot dot) in a pathname.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application&amp;#39;s unrestricted use of the render method and providing a .. (dot dot) in a pathname.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-0752</guid>
    </item>
    <item>
      <title>GHSA-xrr4-p6fq-hjg7 — Directory traversal vulnerability in Action View in Ruby on Rails</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xrr4-p6fq-hjg7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionview, RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application&amp;#39;s unrestricted use of the render method and providing a `..` (dot dot) in a pathname.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: actionview, RubyGems: actionpack&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application&amp;#39;s unrestricted use of the render method and providing a `..` (dot dot) in a pathname.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xrr4-p6fq-hjg7</guid>
    </item>
    <item>
      <title>gsd-2016-0752</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-0752</link>
      <description>gsd-2016-0752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-0752</guid>
    </item>
    <item>
      <title>RHSA-2016:0296 — Red Hat Security Advisory: rh-ror41 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2016:0296</link>
      <description>&lt;p&gt;rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller rubygem-activerecord: Nested attributes rejection proc bypass in Active Record rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack rubygem-actionpack: possible object leak and denial of service attack in Action Pack rubygem-actionpack: directory traversal flaw in Action View rubygem-activerecord: possible input validation circumvention in Active Model&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller rubygem-activerecord: Nested attributes rejection proc bypass in Active Record rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack rubygem-actionpack: possible object leak and denial of service attack in Action Pack rubygem-actionpack: directory traversal flaw in Action View rubygem-activerecord: possible input validation circumvention in Active Model&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2016:0296</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:0456-1 — Security update for rubygem-actionview-4_2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:0456-1</link>
      <description>&lt;p&gt;Security update for rubygem-actionview-4_2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rubygem-actionview-4_2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:0456-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2016-0752</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0752</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: rails&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application&amp;#39;s unrestricted use of the render method and providing a .. (dot dot) in a pathname.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: rails&lt;/p&gt;
&lt;p&gt;Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application&amp;#39;s unrestricted use of the render method and providing a .. (dot dot) in a pathname.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-0752</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1085 — Ruby on Rails: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1085</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Sicherheitsfunktionen zu umgehen, um Dateien zu manipulieren oder um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um Sicherheitsfunktionen zu umgehen, um Dateien zu manipulieren oder um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1085</guid>
    </item>
  </channel>
</rss>
