Логотип exploitDog
product: "symfony"
Консоль
Логотип exploitDog

exploitDog

product: "symfony"

Количество 244

Количество 244

nvd логотип

CVE-2016-2403

больше 8 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-2403

больше 8 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1902

около 9 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-1902

около 9 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-1902

около 9 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8125

больше 9 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-8125

больше 9 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-8125

больше 9 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8124

больше 9 лет назад

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-8124

больше 9 лет назад

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-8124

больше 9 лет назад

Session fixation vulnerability in the "Remember Me" login feature in S ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-4050

около 10 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
EPSS: Высокий
nvd логотип

CVE-2015-4050

около 10 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
EPSS: Высокий
debian логотип

CVE-2015-4050

около 10 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through ...

CVSS2: 4.3
EPSS: Высокий
ubuntu логотип

CVE-2015-2308

почти 10 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2308

почти 10 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2308

почти 10 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in S ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-5958

больше 10 лет назад

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-5958

больше 10 лет назад

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2. ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-4752

больше 5 лет назад

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
debian логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3 ...

CVSS3: 7.5
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...

CVSS2: 7.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in S ...

CVSS2: 6.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
76%
Высокий
около 10 лет назад
nvd логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
76%
Высокий
около 10 лет назад
debian логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through ...

CVSS2: 4.3
76%
Высокий
около 10 лет назад
ubuntu логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in S ...

CVSS2: 6.8
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

CVSS2: 5
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2. ...

CVSS2: 5
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2013-4752

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу