VYPR
Vendor

Redcarpet Project

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2020-26298MedJan 11, 2021
    risk 0.37cvss 6.8epss 0.02

    Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when…

  • CVE-2015-5147Jul 14, 2015
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the header_anchor function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

  • CVE-2006-2703Jun 1, 2006
    risk 0.00cvss epss 0.01

    The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and execute commands via a man-in-the-middle (MITM) attack.