Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-29312 An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be… Zend Framework after 3.1.3 Fix from $2,3002023-04-04 MEDIUM 6.1 CVE-2021-27888 ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters. Zendto after 6.05-4 Fix from $1,6002021-03-02 CRITICAL 9.8 CVE-2020-8986 lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to g… Zendto Mitigation only Fix from $2,3002020-03-24 HIGH 8.8 CVE-2020-8985 ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality. Zendto Mitigation only Fix from $1,9502020-03-24 HIGH 7.5 CVE-2020-8984 lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header. Zendto Mitigation only Fix from $1,9502020-03-24 MEDIUM 6.1 CVE-2015-3154 CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attack… Zend Framework 1.12.12 / 2.3.8+ Fix from $1,6002020-01-27 CRITICAL 9.8 CVE-2015-0270 Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter. Framework 2.2.10 / 2.3.5+ Fix from $2,3002019-10-25 MEDIUM 6.1 CVE-2018-1000841 Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execu… Zendto 5.15-1+ Fix from $1,6002018-12-20 MEDIUM 6.1 CVE-2018-10230 Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455. Zend Server 9.1.3+ Fix from $1,6002018-04-19 HIGH 7.5 CVE-2015-7503 Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private … Zend Framework Mitigation only Fix from $1,9502017-10-10 MEDIUM 6.1 CVE-2015-3257 Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-s… Diactoros after 1.0.3 Fix from $1,6002017-08-25 CRITICAL 9.1 CVE-2015-1555 Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using s… Zend Framework Mitigation only Fix from $2,3002017-08-07 HIGH 8.8 CVE-2015-1786 Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers. Zend Framework Mitigation only Fix from $1,9502017-06-08 CRITICAL 9.8 CVE-2016-10034EPSS 38% The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor… Zend Framework after 2.4.10 Fix from $2,3002016-12-30 MEDIUM 6.8 CVE-2015-5161EPSS 10% The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under P… Zend Framework No fix yet Fix from $1,6002015-08-25 MEDIUM 6.4 CVE-2014-2684 The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 d… Zendopenid after 2.0.1 Fix from $1,6002014-11-16 MEDIUM 5.0 CVE-2014-2683 Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendSer… Zendrest 1.12.4 / 2.1.6+ Fix from $1,6002014-11-16 MEDIUM 6.8 CVE-2014-2682 Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendSer… Zendrest 1.12.4 / 2.1.6+ Fix from $1,6002014-11-16 MEDIUM 6.4 CVE-2014-2681 Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendSer… Zendrest 1.12.4 / 2.1.6+ Fix from $1,6002014-11-16 MEDIUM 5.0 CVE-2014-8088 The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to … Zend Framework after 1.12.7 Fix from $1,6002014-10-22 HIGH 7.5 CVE-2014-2685 The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 v… Zend Framework after 2.0.1 Fix from $1,9502014-09-04 MEDIUM 5.0 CVE-2012-5657 The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attac… Zend Framework Mitigation only Fix from $1,6002013-05-02 MEDIUM 6.4 CVE-2012-6531 (1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement … Zend Framework Mitigation only Fix from $1,6002013-02-13 MEDIUM 5.0 CVE-2012-6532 (1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers … Zend Framework Mitigation only Fix from $1,6002013-02-13 MEDIUM 6.0 CVE-2012-5382 Untrusted search path vulnerability in the installation functionality in Zend Server 5.6.0 SP4, when installed in the top-level C:\ directory, might … Zend Server No fix yet Fix from $1,6002012-10-11 MEDIUM 5.0 CVE-2011-3825 Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reve… Framework Mitigation only Fix from $1,6002011-09-24 MEDIUM 5.0 CVE-2009-4417 The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages t… Framework after 1.9.6 Fix from $1,6002009-12-24 MEDIUM 6.2 CVE-2007-1370 Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modif… Zend Platform Patch available Fix from $1,6002007-03-09 MEDIUM 6.8 CVE-2006-5900 Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 all… Zend Framework Preview Mitigation only Fix from $1,6002006-11-15 HIGH 7.5 CVE-2006-4431 Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote att… Zend Platform after 2.2.1a Fix from $1,9502006-08-29