Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Symfony MEDIUM 6.1
CVE-2018-12040

Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web sc…

No fix yet
Fix from $1,600 2018-06-13
Symfony CRITICAL 9.8
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, w…

Mitigation only
Fix from $2,300 2017-02-07
Symfony MEDIUM 6.8
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows …

Mitigation only
Fix from $1,600 2015-12-07
Symfony MEDIUM 5.0
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cau…

Mitigation only
Fix from $1,600 2014-12-27
Symfony HIGH 7.5
CVE-2013-1348

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than…

Mitigation only
Fix from $1,950 2014-06-02
Symfony HIGH 7.5
CVE-2013-1397

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml…

Mitigation only
Fix from $1,950 2014-06-02
Symfony MEDIUM 6.8
CVE-2012-6432

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access ar…

Mitigation only
Fix from $1,600 2012-12-27
Symfony MEDIUM 6.4
CVE-2012-6431

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-12-27