CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_h...Show more |
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal m...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreNov 21, 2024 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents...Show more |
11Apple AzulDebian+8 more27Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+24 moreAug 21, 2025 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokog...Show more |
2Debian Nokogiri2Debian Linux NokogiriNov 21, 2024 Dec 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are...Show more |
2Nokogiri Redhat8Cloudforms Management Engine Enterprise MrgNokogiri+5 moreNov 21, 2024 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri before 1.5.4 is vulnerable to XXE attacks |
3Debian NokogiriRedhat7Cloudforms Management Engine Debian LinuxEnterprise Mrg+4 moreNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits |
3Debian NokogiriRedhat7Cloudforms Management Engine Debian LinuxEnterprise Mrg+4 moreNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents |
3Canonical DebianNokogiri3Debian Linux NokogiriUbuntu LinuxNov 21, 2024 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::T...Show more |