Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Zend_framework
(Zend)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 27 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-01-27 | CVE-2015-3154 | CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email. | Zend_framework | N/A | ||
2020-01-03 | CVE-2012-4451 | Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper. | Fedora, Enterprise_linux, Zend_framework | N/A | ||
2019-12-15 | CVE-2014-4913 | ZF2014-03 has a potential cross site scripting vector in multiple view helpers | Debian_linux, Zend_framework | N/A | ||
2019-11-26 | CVE-2011-1939 | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. | Debian_linux, Php, Zend_framework | N/A | ||
2014-11-16 | CVE-2014-2683 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration,... | Zend_framework, Zendopenid, Zendrest, Zendservice_amazon, Zendservice_api, Zendservice_audioscrobbler, Zendservice_nirvanix, Zendservice_slideshare, Zendservice_technorati, Zendservice_windowsazure | N/A | ||
2014-11-16 | CVE-2014-2682 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity... | Zend_framework, Zendopenid, Zendrest, Zendservice_amazon, Zendservice_api, Zendservice_audioscrobbler, Zendservice_nirvanix, Zendservice_slideshare, Zendservice_technorati, Zendservice_windowsazure | N/A | ||
2014-11-16 | CVE-2014-2681 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External... | Zend_framework, Zendopenid, Zendrest, Zendservice_amazon, Zendservice_api, Zendservice_audioscrobbler, Zendservice_nirvanix, Zendservice_slideshare, Zendservice_technorati, Zendservice_windowsazure | N/A | ||
2016-12-30 | CVE-2016-10034 | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address. | Zend\-Mail, Zend_framework | 9.8 | ||
2016-06-07 | CVE-2015-7695 | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query. | Debian_linux, Zend_framework | 9.8 | ||
2017-10-10 | CVE-2015-7503 | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key. | Zend_framework | 7.5 |