Zend Framework 2.4.0 Release Candidate 7

CPE Details

Zend Framework 2.4.0 Release Candidate 7
2.4.0
2019-06-18
17h17 +00:00
2019-06-18
17h17 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:zend:zend_framework:2.4.0:rc7:*:*:*:*:*:*

Informations

Vendor

zend

Product

zend_framework

Version

2.4.0

Update

rc7

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-29312 2023-04-04 00h00 +00:00 An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020.
9.8
Critique
CVE-2015-3154 2020-01-27 14h02 +00:00 CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
6.1
Moyen
CVE-2015-7503 2017-10-10 14h00 +00:00 Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
7.5
Haute
CVE-2016-10034 2016-12-30 18h00 +00:00 The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
9.8
Critique
CVE-2015-5723 2016-06-07 12h00 +00:00 Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
7.8
Haute
CVE-2015-5161 2015-08-25 15h00 +00:00 The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.
6.8