Skip to main content

Vendor/product archive

zend / zend_framework CVEs

Beta · best-effort

27 CVEs tagged to zend / zend_framework11 Critical, 4 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2020-29312

Published Apr 4, 2023

An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3007

Published Jan 4, 2021

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, re…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2015-3154

Published Jan 27, 2020

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP h…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4914

Published Dec 29, 2017

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspeci…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7503

Published Oct 10, 2017

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1555

Published Aug 7, 2017

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1786

Published Jun 8, 2017

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6233

Published Feb 17, 2017

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4861

Published Feb 17, 2017

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to r…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10034

Published Dec 30, 2016

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote at…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-7695

Published Jun 7, 2016

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5723

Published Jun 7, 2016

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM befor…

CVSS 7.8 · High

CVE-2015-5161

Published Aug 25, 2015

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environme…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2684

Published Nov 16, 2014

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2683

Published Nov 16, 2014

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_Sli…

CVSS 5.0 · Medium

CVE-2014-2682

Published Nov 16, 2014

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_Sli…

CVSS 6.8 · Medium

CVE-2014-2681

Published Nov 16, 2014

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_Sli…

CVSS 6.4 · Medium

CVE-2014-8088

Published Oct 22, 2014

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2685

Published Sep 4, 2014

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5657

Published May 2, 2013

The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6532

Published Feb 13, 2013

(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2