Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Zend_framework
(Zend)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 27 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-01-03 | CVE-2012-4451 | Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper. | Fedora, Enterprise_linux, Zend_framework | N/A | ||
2019-12-15 | CVE-2014-4913 | ZF2014-03 has a potential cross site scripting vector in multiple view helpers | Debian_linux, Zend_framework | N/A | ||
2019-11-26 | CVE-2011-1939 | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. | Debian_linux, Php, Zend_framework | N/A | ||
2014-11-16 | CVE-2014-2683 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration,... | Zend_framework, Zendopenid, Zendrest, Zendservice_amazon, Zendservice_api, Zendservice_audioscrobbler, Zendservice_nirvanix, Zendservice_slideshare, Zendservice_technorati, Zendservice_windowsazure | N/A | ||
2014-11-16 | CVE-2014-2682 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity... | Zend_framework, Zendopenid, Zendrest, Zendservice_amazon, Zendservice_api, Zendservice_audioscrobbler, Zendservice_nirvanix, Zendservice_slideshare, Zendservice_technorati, Zendservice_windowsazure | N/A | ||
2014-11-16 | CVE-2014-2681 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External... | Zend_framework, Zendopenid, Zendrest, Zendservice_amazon, Zendservice_api, Zendservice_audioscrobbler, Zendservice_nirvanix, Zendservice_slideshare, Zendservice_technorati, Zendservice_windowsazure | N/A | ||
2016-12-30 | CVE-2016-10034 | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address. | Zend\-Mail, Zend_framework | 9.8 | ||
2016-06-07 | CVE-2015-7695 | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query. | Debian_linux, Zend_framework | 9.8 | ||
2017-10-10 | CVE-2015-7503 | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key. | Zend_framework | 7.5 | ||
2015-08-25 | CVE-2015-5161 | The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters. | Zend_framework | N/A |