Search CVE reports


Toggle filters

11 – 20 of 22 results


CVE-2015-7695

Medium priority
Vulnerable

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.

2 affected packages

zend-framework, zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zend-framework Not in release Not in release Not in release Not in release Vulnerable
zendframework Not in release Not in release Not in release Not affected Not in release
Show less packages

CVE-2014-2684

Medium priority
Ignored

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity...

1 affected package

zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zendframework
Show less packages

CVE-2014-2683

Medium priority
Ignored

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati,...

1 affected package

zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zendframework
Show less packages

CVE-2014-2682

Medium priority
Ignored

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati,...

1 affected package

zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zendframework
Show less packages

CVE-2014-2681

Medium priority
Ignored

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati,...

1 affected package

zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zendframework
Show less packages

CVE-2014-8088

Medium priority
Vulnerable

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an...

2 affected packages

zend-framework, zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zend-framework Not in release Not in release Not in release Not in release Vulnerable
zendframework Not in release Not in release Not in release Not affected Not in release
Show less packages

CVE-2014-2685

Medium priority
Ignored

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field...

1 affected package

zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zendframework
Show less packages

CVE-2012-5657

Medium priority
Vulnerable

The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and...

2 affected packages

zend-framework, zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zend-framework Not in release Not in release Not in release Not in release Vulnerable
zendframework Not in release Not in release Not in release Not affected Not in release
Show less packages

CVE-2012-6532

Medium priority
Vulnerable

(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (CPU consumption) via recursive or circular...

2 affected packages

zend-framework, zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zend-framework Not in release Not in release Not in release Not in release Vulnerable
zendframework Not in release Not in release Not in release Not affected Not in release
Show less packages

CVE-2012-6531

Medium priority
Vulnerable

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create...

2 affected packages

zend-framework, zendframework

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
zend-framework Not in release Not in release Not in release Not in release Vulnerable
zendframework Not in release Not in release Not in release Not affected Not in release
Show less packages