Search CVE reports
1 – 9 of 9 results
CVE-2022-23476
Medium priorityNokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This...
1 affected packages
ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-nokogiri | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2022-29181
Medium priorityNokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory...
1 affected packages
ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-nokogiri | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2022-24836
Medium priorityNokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users...
1 affected packages
ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-nokogiri | Not affected | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
CVE-2021-41098
Medium priorityNokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby only, the SAX parser resolves external entities by default. Users of Nokogiri on...
1 affected packages
ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-nokogiri | — | — | Not affected | Not affected | Not affected |
CVE-2020-26247
Medium priorityNokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted...
1 affected packages
ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-nokogiri | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
CVE-2012-6685
Medium priorityNokogiri before 1.5.4 is vulnerable to XXE attacks
2 affected packages
libnokogiri-ruby, ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libnokogiri-ruby | — | — | — | — | Not in release |
ruby-nokogiri | — | — | — | — | Not affected |
CVE-2013-6461
Medium priorityNokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
2 affected packages
libnokogiri-ruby, ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libnokogiri-ruby | — | — | — | — | — |
ruby-nokogiri | — | — | — | — | — |
CVE-2013-6460
Medium priorityNokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
2 affected packages
libnokogiri-ruby, ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libnokogiri-ruby | — | — | — | — | — |
ruby-nokogiri | — | — | — | — | — |
CVE-2019-5477
Medium priorityA command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented...
1 affected packages
ruby-nokogiri
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-nokogiri | — | Not affected | Not affected | Fixed | Fixed |