CVE-2014-5011
published 2020-01-10CVE-2014-5011: DOMPDF before 0.6.2 allows Information Disclosure.
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.63%
73.2th percentile
DOMPDF before 0.6.2 allows Information Disclosure.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php-dompdf | < php-dompdf 0.6.2+dfsg-1 (bookworm) | php-dompdf 0.6.2+dfsg-1 (bookworm) |
| dompdf | dompdf | >= 0.6 < 0.6.2 | 0.6.2 |
| dompdf_project | dompdf | < 0.6.2 | 0.6.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
php-dompdf vulnerabilities
osv·2023-08-10·CVSS 6.5
CVE-2014-5011 [MEDIUM] php-dompdf vulnerabilities
php-dompdf vulnerabilities
USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the
corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly vali
OSV
php-dompdf vulnerabilities
osv·2023-08-08·CVSS 6.5
CVE-2014-5011 [MEDIUM] php-dompdf vulnerabilities
php-dompdf vulnerabilities
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced both a remote base and a local file, which could
result in the bypass of a chroot check. An atta
OSV
DOMPDF Information Disclosure
osv·2022-05-17
CVE-2014-5011 [MEDIUM] DOMPDF Information Disclosure
DOMPDF Information Disclosure
DOMPDF before 0.6.2 allows Information Disclosure.
GHSA
DOMPDF Information Disclosure
ghsa·2022-05-17
CVE-2014-5011 [MEDIUM] CWE-200 DOMPDF Information Disclosure
DOMPDF Information Disclosure
DOMPDF before 0.6.2 allows Information Disclosure.
OSV
CVE-2014-5011: DOMPDF before 0
osv·2020-01-10·CVSS 6.5
CVE-2014-5011 [MEDIUM] CVE-2014-5011: DOMPDF before 0
DOMPDF before 0.6.2 allows Information Disclosure.
Ubuntu
Dompdf vulnerabilities
vendor_ubuntu·2023-08-10·CVSS 6.5
CVE-2021-3838 [MEDIUM] Dompdf vulnerabilities
Title: Dompdf vulnerabilities
Summary: Several security issues were fixed in Dompdf.
USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the
corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021
Ubuntu
Dompdf vulnerabilities
vendor_ubuntu·2023-08-08·CVSS 6.5
CVE-2014-5011 [MEDIUM] Dompdf vulnerabilities
Title: Dompdf vulnerabilities
Summary: Several security issues were fixed in Dompdf.
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced both a remote base and a local file,
Debian
CVE-2014-5011: php-dompdf - DOMPDF before 0.6.2 allows Information Disclosure.
vendor_debian·2014·CVSS 6.5
CVE-2014-5011 [MEDIUM] CVE-2014-5011: php-dompdf - DOMPDF before 0.6.2 allows Information Disclosure.
DOMPDF before 0.6.2 allows Information Disclosure.
Scope: local
bookworm: resolved (fixed in 0.6.2+dfsg-1)
bullseye: resolved (fixed in 0.6.2+dfsg-1)
sid: resolved (fixed in 0.6.2+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-10
Published