Skip to main content

Vendor archive

dompdf CVEs

Beta · best-effort

4 CVEs tagged to vendor dompdf0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-25117

Published Feb 21, 2024

php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50252

Published Dec 12, 2023

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `<use>` tag that references an `<image>` tag, it merges the attributes from the `<use…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50251

Published Dec 12, 2023

php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when parsing the attributes passed to a `use` tag inside an svg document, an attacker can cause the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2383

Published Apr 28, 2014

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1