CVE-2014-2681
- EPSS 3.45%
- Published 16.11.2014 00:59:00
- Last modified 12.04.2025 10:46:40
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2....
- EPSS 0.61%
- Published 22.10.2014 14:55:07
- Last modified 12.04.2025 10:46:40
The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bin...
CVE-2014-2685
- EPSS 0.84%
- Published 04.09.2014 17:55:04
- Last modified 12.04.2025 10:46:40
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remot...
- EPSS 0.72%
- Published 02.05.2013 14:55:05
- Last modified 11.04.2025 00:51:21
The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of ...
CVE-2012-3363
- EPSS 55.12%
- Published 13.02.2013 17:55:01
- Last modified 11.04.2025 00:51:21
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE...
- EPSS 0.47%
- Published 13.02.2013 17:55:01
- Last modified 11.04.2025 00:51:21
(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers to cause a denial of service (CPU consumption) via recursive or circular references in an XML entity ...
CVE-2012-6531
- EPSS 0.91%
- Published 13.02.2013 17:55:01
- Last modified 11.04.2025 00:51:21
(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an extern...