CVE-2014-5013
published 2020-01-10CVE-2014-5013: DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.56%
90.4th percentile
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php-dompdf | < php-dompdf 0.6.2+dfsg-1 (bookworm) | php-dompdf 0.6.2+dfsg-1 (bookworm) |
| dompdf | dompdf | >= 0.6 < 0.6.2 | 0.6.2 |
| dompdf_project | dompdf | < 0.6.2 | 0.6.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dompdf vulnerabilities
vendor_ubuntu·2023-08-10·CVSS 6.5
CVE-2021-3838 [MEDIUM] Dompdf vulnerabilities
Title: Dompdf vulnerabilities
Summary: Several security issues were fixed in Dompdf.
USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the
corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021
Ubuntu
Dompdf vulnerabilities
vendor_ubuntu·2023-08-08·CVSS 6.5
CVE-2014-5011 [MEDIUM] Dompdf vulnerabilities
Title: Dompdf vulnerabilities
Summary: Several security issues were fixed in Dompdf.
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced both a remote base and a local file,
Debian
CVE-2014-5013: php-dompdf - DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-23...
vendor_debian·2014·CVSS 6.8
CVE-2014-5013 [MEDIUM] CVE-2014-5013: php-dompdf - DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-23...
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
Scope: local
bookworm: resolved (fixed in 0.6.2+dfsg-1)
bullseye: resolved (fixed in 0.6.2+dfsg-1)
sid: resolved (fixed in 0.6.2+dfsg-1)
OSV
php-dompdf vulnerabilities
osv·2023-08-10·CVSS 6.5
CVE-2014-5011 [MEDIUM] php-dompdf vulnerabilities
php-dompdf vulnerabilities
USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the
corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly vali
OSV
php-dompdf vulnerabilities
osv·2023-08-08·CVSS 6.5
CVE-2014-5011 [MEDIUM] php-dompdf vulnerabilities
php-dompdf vulnerabilities
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced both a remote base and a local file, which could
result in the bypass of a chroot check. An atta
OSV
DOMPDF Remote Code Execution
osv·2022-05-17·CVSS 6.8
CVE-2014-5013 [MEDIUM] DOMPDF Remote Code Execution
DOMPDF Remote Code Execution
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
GHSA
DOMPDF Remote Code Execution
ghsa·2022-05-17·CVSS 6.8
CVE-2014-5013 [MEDIUM] CWE-94 DOMPDF Remote Code Execution
DOMPDF Remote Code Execution
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
OSV
CVE-2014-5013: DOMPDF before 0
osv·2020-01-10·CVSS 6.8
CVE-2014-5013 [MEDIUM] CVE-2014-5013: DOMPDF before 0
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-10
Published