Zend Framework vulnerabilities

28 known vulnerabilities affecting zend/zend_framework.

Total CVEs
28
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH4MEDIUM12

Vulnerabilities

Page 2 of 2
CVE-2014-2684MEDIUMCVSS 6.4≤ 1.12.42014-11-16
CVE-2014-2684 [MEDIUM] CWE-264 CVE-2014-2684: The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_C The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to bypass authentication and spoof arbi
nvd
CVE-2014-2682MEDIUMCVSS 6.8fixed in 1.12.4≥ 2.1.0, < 2.1.6+1 more2014-11-16
CVE-2014-2682 [MEDIUM] CVE-2014-2682: Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpen Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly
nvd
CVE-2014-8088MEDIUMCVSS 5.0≤ 1.12.7v1.12.0+15 more2014-10-22
CVE-2014-8088 [MEDIUM] CWE-287 CVE-2014-8088: The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 a The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.
nvd
CVE-2014-2685HIGHCVSS 7.5≤ 1.12.3v1.0.0+63 more2014-09-04
CVE-2014-2685 [HIGH] CWE-287 CVE-2014-2685: The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_C The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
nvd
CVE-2012-5657MEDIUMCVSS 5.0v1.11.0v1.11.1+13 more2013-05-02
CVE-2012-5657 [MEDIUM] CWE-200 CVE-2012-5657: The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1. The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.
nvd
CVE-2012-3363CRITICALCVSS 9.1PoC≥ 1.0.0, < 1.11.12v1.12.02013-02-13
CVE-2012-3363 [CRITICAL] CWE-611 CVE-2012-3363: Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle S Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
nvd
CVE-2012-6531MEDIUMCVSS 6.4v1.0.4v1.5.0+54 more2013-02-13
CVE-2012-6531 [MEDIUM] CVE-2012-6531: (1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x befor (1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection atta
nvd
CVE-2012-6532MEDIUMCVSS 5.0v1.0.4v1.5.0+54 more2013-02-13
CVE-2012-6532 [MEDIUM] CWE-399 CVE-2012-6532: (1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 (1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (CPU consumption) via recursive or circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack.
nvd