Search CVE reports
11 – 20 of 22 results
CVE-2015-7695
Medium priorityThe PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
2 affected packages
zend-framework, zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zend-framework | Not in release | Not in release | Not in release | Not in release | Vulnerable |
zendframework | Not in release | Not in release | Not in release | Not affected | Not in release |
CVE-2014-2684
Medium priorityThe GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity...
1 affected package
zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zendframework | — | — | — | — | — |
CVE-2014-2683
Medium priorityZend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati,...
1 affected package
zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zendframework | — | — | — | — | — |
CVE-2014-2682
Medium priorityZend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati,...
1 affected package
zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zendframework | — | — | — | — | — |
CVE-2014-2681
Medium priorityZend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati,...
1 affected package
zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zendframework | — | — | — | — | — |
CVE-2014-8088
Medium priorityThe (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an...
2 affected packages
zend-framework, zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zend-framework | Not in release | Not in release | Not in release | Not in release | Vulnerable |
zendframework | Not in release | Not in release | Not in release | Not affected | Not in release |
CVE-2014-2685
Medium priorityThe GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field...
1 affected package
zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zendframework | — | — | — | — | — |
CVE-2012-5657
Medium priorityThe (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and...
2 affected packages
zend-framework, zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zend-framework | Not in release | Not in release | Not in release | Not in release | Vulnerable |
zendframework | Not in release | Not in release | Not in release | Not affected | Not in release |
CVE-2012-6532
Medium priority(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (CPU consumption) via recursive or circular...
2 affected packages
zend-framework, zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zend-framework | Not in release | Not in release | Not in release | Not in release | Vulnerable |
zendframework | Not in release | Not in release | Not in release | Not affected | Not in release |
CVE-2012-6531
Medium priority(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create...
2 affected packages
zend-framework, zendframework
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
zend-framework | Not in release | Not in release | Not in release | Not in release | Vulnerable |
zendframework | Not in release | Not in release | Not in release | Not affected | Not in release |