← Back

CVE-2014-0081

nvd nist
Published: Feb 20, 2014Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.

Affected (186)

Show all products
2 products
Rails
Ruby On Rails
1 product
Opensuse
Opensuse
2 products
Cloudforms
Enterprise Linux
Configuration A
182 vulnerable
Vulnerable SoftwareAffected Versions
Rubyonrails
Version 0.10.0
Version 0.10.1
Version 0.11.0
Version 0.11.1
Version 0.12.0
Version 0.12.1
Version 0.13.0
Version 0.13.1
Version 0.14.1
Version 0.14.2
Version 0.14.3
Version 0.14.4
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9.4.1
Version 0.9.4
Version 1.0.0
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.2.0
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.9.5
Version 2.0.0
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.1
Version 2.0.2
Version 2.0.4
Version 2.1.0
Version 2.1.1
Version 2.1.2
Version 2.2.0
Version 2.2.1
Version 2.2.2
Version 2.3.0
Version 2.3.10
Version 2.3.11
Version 2.3.12
Version 2.3.13
Version 2.3.14
Version 2.3.15
Version 2.3.16
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.9
Version 3.0.0
Version 3.0.0 beta2
Version 3.0.0 beta3
Version 3.0.0 beta4
Version 3.0.0 beta
Version 3.0.0 rc2
Version 3.0.0 rc
Version 3.0.10
Version 3.0.10 rc1
Version 3.0.11
Version 3.0.12
Version 3.0.12 rc1
Version 3.0.13
Version 3.0.13 rc1
Version 3.0.14
Version 3.0.16
Version 3.0.17
Version 3.0.18
Version 3.0.19
Version 3.0.1
Version 3.0.1 pre
Version 3.0.20
Version 3.0.2
Version 3.0.2 pre
Version 3.0.3
Version 3.0.4 rc1
Version 3.0.5
Version 3.0.5 rc1
Version 3.0.6
Version 3.0.6 rc1
Version 3.0.6 rc2
Version 3.0.7
Version 3.0.7 rc1
Version 3.0.7 rc2
Version 3.0.8
Version 3.0.8 rc1
Version 3.0.8 rc2
Version 3.0.8 rc3
Version 3.0.8 rc4
Version 3.0.9
Version 3.0.9 rc1
Version 3.0.9 rc2
Version 3.0.9 rc3
Version 3.0.9 rc4
Version 3.0.9 rc5
Version 3.1.0
Version 3.1.0 beta1
Version 3.1.0 rc1
Version 3.1.0 rc2
Version 3.1.0 rc3
Version 3.1.0 rc4
Version 3.1.0 rc5
Version 3.1.0 rc6
Version 3.1.0 rc7
Version 3.1.0 rc8
Version 3.1.10
Version 3.1.1
Version 3.1.1 rc1
Version 3.1.1 rc2
Version 3.1.1 rc3
Version 3.1.2
Version 3.1.2 rc1
Version 3.1.2 rc2
Version 3.1.3
Version 3.1.4
Version 3.1.4 rc1
Version 3.1.5
Version 3.1.5 rc1
Version 3.1.6
Version 3.1.7
Version 3.1.8
Version 3.1.9
Version 3.2.0
Version 3.2.0 rc1
Version 3.2.0 rc2
Version 3.2.10
Version 3.2.11
Version 3.2.12
Version 3.2.13
Version 3.2.13 rc1
Version 3.2.13 rc2
Version 3.2.15
Version 3.2.15 rc3
Version 3.2.1
Version 3.2.2
Version 3.2.2 rc1
Version 3.2.3
Version 3.2.3 rc1
Version 3.2.3 rc2
Version 3.2.4
Version 3.2.4 rc1
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2.9
Version 4.0.0
Version 4.0.0 beta
Version 4.0.0 rc1
Version 4.0.0 rc2
Version 4.0.1
Version 4.0.1 rc1
Version 4.0.1 rc2
Version 4.0.1 rc3
Version 4.0.1 rc4
Version 4.0.2
Version 4.1.0 beta1
Rubyonrails
Up to 3.2.16
Version 0.5.0
Version 0.5.5
Version 0.5.6
Version 0.5.7
Version 0.6.0
Version 0.6.5
Version 0.7.0
Version 0.8.0
Version 0.8.5
Version 0.9.0
Version 3.0.4
Version 3.2.14
Version 3.2.14 rc1
Version 3.2.14 rc2
Version 3.2.15 rc1
Version 3.2.15 rc2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.1
Version 12.3
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
Version 6.0

References (16)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Permissions Required
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.