CVE-2023-23924
- EPSS 3.57%
- Veröffentlicht 01.02.2023 00:15:10
- Zuletzt bearbeitet 21.11.2024 07:47:06
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attac...
CVE-2022-41343
- EPSS 4.42%
- Veröffentlicht 25.09.2022 19:15:09
- Zuletzt bearbeitet 22.05.2025 15:16:02
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
CVE-2022-2400
- EPSS 1.16%
- Veröffentlicht 18.07.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:54
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
CVE-2022-0085
- EPSS 0.96%
- Veröffentlicht 28.06.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:37:52
Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.
CVE-2022-28368
- EPSS 82.44%
- Veröffentlicht 03.04.2022 03:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:13
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
CVE-2014-5011
- EPSS 1.49%
- Veröffentlicht 10.01.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 02:11:16
DOMPDF before 0.6.2 allows Information Disclosure.
CVE-2014-5013
- EPSS 4.48%
- Veröffentlicht 10.01.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 02:11:16
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
CVE-2014-5012
- EPSS 1.23%
- Veröffentlicht 10.01.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 02:11:16
DOMPDF before 0.6.2 allows denial of service.