Dompdf

Dompdf

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.64%
  • Veröffentlicht 28.07.2026 20:42:57
  • Zuletzt bearbeitet 04.08.2026 16:34:42

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD. A 58-byte...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 28.07.2026 20:41:02
  • Zuletzt bearbeitet 04.08.2026 15:54:55

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document containing a single i...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 28.07.2026 20:19:22
  • Zuletzt bearbeitet 04.08.2026 15:21:31

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF fi...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 28.07.2026 20:17:36
  • Zuletzt bearbeitet 04.08.2026 16:39:54

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a  data:  URI, because dompdf processes...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 28.07.2026 19:28:43
  • Zuletzt bearbeitet 05.08.2026 16:37:42

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with  realpath() . Because normalization strips the trailing directo...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 28.07.2026 19:23:45
  • Zuletzt bearbeitet 05.08.2026 16:29:57

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// pro...

  • EPSS 39.23%
  • Veröffentlicht 28.04.2014 14:09:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://fil...