Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Symfony HIGH 7.5
CVE-2017-16654

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle reader…

Fix: after 3.8.30
Fix from $1,950 2018-08-06
Symfony MEDIUM 6.5
CVE-2017-16790

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request…

Fix: after 3.3.12
Fix from $1,600 2018-08-06
Symfony MEDIUM 5.9
CVE-2017-16653

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in …

Fix: after 3.8.30
Fix from $1,600 2018-08-06
Symfony HIGH 7.2
CVE-2018-14774

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 throug…

Fix: after 4.1.2
Fix from $1,950 2018-08-03
Symfony MEDIUM 6.5
CVE-2018-14773EPSS 58%

An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 t…

Fix: 8.5.6+
Fix from $1,600 2018-08-03
Symfony MEDIUM 6.1
CVE-2017-18343EPSS 6%

The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during except…

Fix: 2.7.33 / 2.8.26+
Fix from $1,600 2018-07-20
Symfony MEDIUM 6.1
CVE-2018-12040

Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web sc…

No fix yet
Fix from $1,600 2018-06-13
Symfony CRITICAL 9.8
CVE-2018-11407

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It all…

Fix: 2.8.37 / 3.3.17+
Fix from $2,300 2018-06-13
Symfony MEDIUM 6.1
CVE-2018-11408

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and…

Fix: 2.7.48 / 2.8.41+
Fix from $1,600 2018-06-13
Symfony HIGH 8.8
CVE-2018-11406

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and …

Fix: 2.7.48 / 2.8.41+
Fix from $1,950 2018-06-13
Symfony HIGH 8.1
CVE-2018-11385

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and …

Fix: 2.7.48 / 2.8.41+
Fix from $1,950 2018-06-13
Symfony MEDIUM 6.1
CVE-2017-16652

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSucce…

Fix: 2.7.38 / 2.8.31+
Fix from $1,600 2018-06-13
Symfony MEDIUM 5.9
CVE-2018-11386

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11…

Fix: 2.7.48 / 2.8.41+
Fix from $1,600 2018-06-13
Symfony CRITICAL 9.8
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, w…

Mitigation only
Fix from $2,300 2017-02-07
Symfony HIGH 7.5
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x…

Fix: after 2.3.40
Fix from $1,950 2016-06-01
Symfony HIGH 7.5
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack …

Patch available
Fix from $1,950 2015-12-07
Symfony MEDIUM 6.8
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows …

Mitigation only
Fix from $1,600 2015-12-07
Symfony MEDIUM 6.8
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6…

Patch available
Fix from $1,600 2015-06-24
Symfony MEDIUM 5.0
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cau…

Mitigation only
Fix from $1,600 2014-12-27
Symfony HIGH 7.5
CVE-2013-1348

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than…

Mitigation only
Fix from $1,950 2014-06-02
Symfony HIGH 7.5
CVE-2013-1397

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml…

Mitigation only
Fix from $1,950 2014-06-02
Symfony MEDIUM 6.8
CVE-2012-6432

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access ar…

Mitigation only
Fix from $1,600 2012-12-27
Symfony MEDIUM 6.4
CVE-2012-6431

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-12-27
Symfony MEDIUM 5.0
CVE-2012-5574

lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

Fix: after 1.4.19
Fix from $1,600 2012-12-18