İçeriğe atla
Noroxi

Phusion kayıtları

phusion üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%92,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2018-12026
    40Planlayın

    During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applicatio

    KritikCVSS 9,8İstismar yokEPSS %2

    phusion · passenger17 Haz 2018

  • CVE-2018-12027
    35İzleyin

    An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following

    YüksekCVSS 8,8İstismar yokEPSS %1

    phusion · passenger17 Haz 2018

  • CVE-2013-7134
    31İzleyin

    Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key

    YüksekCVSS 7,5İstismar yokEPSS %2

    phusion · juvia29 Nis 2014

  • CVE-2012-6135
    31İzleyin

    RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

    YüksekCVSS 7,5İstismar yokEPSS %2

    phusion · passenger19 Kas 2019

  • CVE-2018-12028
    31İzleyin

    An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious applic

    YüksekCVSS 7,8İstismar yokEPSS %1

    phusion · passenger17 Haz 2018

  • CVE-2016-10345
    31İzleyin

    In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local a

    YüksekCVSS 7,8İstismar yokEPSS %0

    phusion · passenger18 Nis 2017

  • CVE-2025-26803
    30İzleyin

    The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an inva

    YüksekCVSS 7,5İstismar yokEPSS %1

    phusion · passenger24 Şub 2025

  • CVE-2018-12029
    28İzleyin

    A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-stan

    YüksekCVSS 7,0İstismar yokEPSS %0

    phusion · passenger17 Haz 2018

  • CVE-2018-12615
    21İzleyin

    An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2.

    OrtaCVSS 5,3İstismar yokEPSS %1

    phusion · passenger21 Haz 2018

  • CVE-2013-2119
    18İzleyin

    Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application sta

    OrtaCVSS 4,6İstismar yokEPSS %0

    phusion · passenger3 Oca 2014

  • CVE-2017-16355
    18İzleyin

    In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if

    OrtaCVSS 4,7İstismar yokEPSS %0

    phusion · passenger14 Ara 2017

  • CVE-2013-4136
    17İzleyin

    ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the o

    OrtaCVSS 4,4İstismar yokEPSS %0

    phusion · passenger30 Eyl 2013

  • CVE-2014-1831
    8İzleyin

    Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid

    DüşükCVSS 2,1İstismar yokEPSS %0

    phusion · passenger19 Şub 2015

  • CVE-2014-1832
    8İzleyin

    Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (

    DüşükCVSS 2,1İstismar yokEPSS %0

    phusion · passenger19 Şub 2015