Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zend vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2015-3257
Zend/Diactoros/Uri::filterPath in zend-diactoros prior to 1.0.4 does not properly sanitize path input, which allows remote malicious users to perform cross-site scripting (XSS) or open redirect attacks.
Zend Diactoros
6.4
CVSSv2
CVE-2015-1555
Zend/Session/SessionManager in Zend Framework 2.2.x prior to 2.2.9, 2.3.x prior to 2.3.4 allows remote malicious users to create valid sessions without using session validators.
Zend Zend Framework 2.2.4
Zend Zend Framework 2.2.2
Zend Zend Framework 2.3.0
Zend Zend Framework 2.2.1
Zend Zend Framework 2.2.0
Zend Zend Framework 2.3.2
Zend Zend Framework 2.3.1
Zend Zend Framework 2.2.8
Zend Zend Framework 2.2.7
Zend Zend Framework 2.2.6
Zend Zend Framework 2.2.5
Zend Zend Framework 2.2.3
Zend Zend Framework 2.3.3
6.8
CVSSv2
CVE-2017-11628
In PHP prior to 5.6.31, 7.x prior to 7.0.21, and 7.1.x prior to 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications th...
Php Php
Php Php 7.0.11
Php Php 7.0.4
Php Php 7.0.19
Php Php 7.0.3
Php Php 7.0.1
Php Php 7.0.12
Php Php 7.0.13
Php Php 7.0.16
Php Php 7.0.7
Php Php 7.0.14
Php Php 7.0.20
Php Php 7.0.15
Php Php 7.0.18
Php Php 7.0.2
Php Php 7.0.9
Php Php 7.0.8
Php Php 7.0.17
Php Php 7.0.5
Php Php 7.0.10
Php Php 7.0.0
Php Php 7.0.6
6.8
CVSSv2
CVE-2015-1786
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x prior to 2.3.6 via null or malformed token identifiers.
Zend Zend Framework 2.3.3
Zend Zend Framework 2.3.4
Zend Zend Framework 2.3.5
Zend Zend Framework 2.3.1
Zend Zend Framework 2.3.0
Zend Zend Framework 2.3.2
7.5
CVSSv2
CVE-2017-9119
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows malicious users to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
Php Php 7.1.5
Netapp Clustered Data Ontap -
Netapp Storage Automation Store -
7.5
CVSSv2
CVE-2017-8923
The zend_string_extend function in Zend/zend_string.h in PHP up to and including 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified ot...
Php Php
5
CVSSv2
CVE-2017-6441
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows malicious users to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of thi...
Php Php 7.1.2
6.8
CVSSv2
CVE-2016-10168
Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) prior to 2.2.4 allows remote malicious users to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.
Libgd Libgd
7.5
CVSSv2
CVE-2016-4861
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework prior to 1.12.20 might allow remote malicious users to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
Fedoraproject Fedora 25
Fedoraproject Fedora 24
Fedoraproject Fedora 23
Zend Zend Framework
7.5
CVSSv2
CVE-2016-6233
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework prior to 1.12.19 might allow remote malicious users to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
Fedoraproject Fedora 25
Fedoraproject Fedora 24
Fedoraproject Fedora 23
Zend Zend Framework
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »