CVE-2024-56527
- EPSS 0.29%
- Veröffentlicht 27.12.2024 06:15:23
- Zuletzt bearbeitet 03.11.2025 20:16:53
An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
CVE-2024-56522
- EPSS 0.1%
- Veröffentlicht 27.12.2024 05:15:08
- Zuletzt bearbeitet 03.11.2025 20:16:53
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
CVE-2024-56519
- EPSS 0.08%
- Veröffentlicht 27.12.2024 05:15:07
- Zuletzt bearbeitet 03.11.2025 20:16:52
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
CVE-2024-56520
- EPSS 0.07%
- Veröffentlicht 27.12.2024 05:15:07
- Zuletzt bearbeitet 03.11.2025 20:16:52
An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 and TrueType fonts is misparsed.
CVE-2024-56521
- EPSS 0.19%
- Veröffentlicht 27.12.2024 05:15:07
- Zuletzt bearbeitet 21.04.2025 15:25:11
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
CVE-2018-17057
- EPSS 59.39%
- Veröffentlicht 14.09.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:47
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.