Dompdf Project

Dompdf

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.57%
  • Veröffentlicht 01.02.2023 00:15:10
  • Zuletzt bearbeitet 21.11.2024 07:47:06

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attac...

Exploit
  • EPSS 4.42%
  • Veröffentlicht 25.09.2022 19:15:09
  • Zuletzt bearbeitet 22.05.2025 15:16:02

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

Exploit
  • EPSS 1.16%
  • Veröffentlicht 18.07.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:00:54

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

Exploit
  • EPSS 0.96%
  • Veröffentlicht 28.06.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:37:52

Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.

Exploit
  • EPSS 82.44%
  • Veröffentlicht 03.04.2022 03:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:13

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

  • EPSS 1.49%
  • Veröffentlicht 10.01.2020 06:15:11
  • Zuletzt bearbeitet 21.11.2024 02:11:16

DOMPDF before 0.6.2 allows Information Disclosure.

  • EPSS 4.48%
  • Veröffentlicht 10.01.2020 06:15:11
  • Zuletzt bearbeitet 21.11.2024 02:11:16

DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

  • EPSS 1.23%
  • Veröffentlicht 10.01.2020 06:15:11
  • Zuletzt bearbeitet 21.11.2024 02:11:16

DOMPDF before 0.6.2 allows denial of service.