VendorsRed Hatsubscription_asset_managerany version
Vulnerabilities

Red Hat Subscription Asset Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2014-0130
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
Published 2014-05-07 · Analyzed
7.5KEVEPSS 0.537
CVE-2012-6685
Nokogiri before 1.5.4 is vulnerable to XXE attacks
Published 2020-02-19 · Modified
7.5EPSS 0.022
CVE-2013-6461
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Published 2019-11-05 · Modified
6.5EPSS 0.022
CVE-2013-6460
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Published 2019-11-05 · Modified
6.5EPSS 0.021
CVE-2013-1823
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
Published 2013-04-02 · Modified
4.3EPSS 0.019
CVE-2012-6119
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
Published 2013-04-02 · Modified
2.1EPSS 0.004