4.3
CVSSv2

CVE-2013-0256

Published: 01/03/2013 Updated: 09/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

darkfish.js in RDoc 2.3.0 up to and including 3.12 and 4.x prior to 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via a crafted URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ruby-lang rdoc

ruby-lang rdoc 4.0.0

ruby-lang ruby 1.9

ruby-lang ruby 1.9.1

ruby-lang ruby 1.9.2

ruby-lang ruby 1.9.3

ruby-lang ruby 2.0

ruby-lang ruby 2.0.0

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

Vendor Advisories

Several security issues were fixed in Ruby ...
Synopsis Moderate: rubygem packages security update Type/Severity Security Advisory: Moderate Topic This update fixes one security issue in multiple rubygem packages forRed Hat OpenShift Enterprise 113The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vul ...
Synopsis Moderate: ruby193-ruby, rubygem-json and rubygem-rdoc security update Type/Severity Security Advisory: Moderate Topic Updated ruby193-ruby, rubygem-json and rubygem-rdoc packages that fix twosecurity issues are now available for Red Hat OpenShift Enterprise 113The Red Hat Security Response Team ...
Synopsis Moderate: Subscription Asset Manager 121 update Type/Severity Security Advisory: Moderate Topic Red Hat Subscription Asset Manager 121, which fixes several securityissues, multiple bugs, and adds various enhancements, is now availableThe Red Hat Security Response Team has rated this update as ...