Логотип exploitDog
product: "symfony"
Консоль
Логотип exploitDog

exploitDog

product: "symfony"

Количество 255

Количество 255

debian логотип

CVE-2017-16652

больше 7 лет назад

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-11365

больше 6 лет назад

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-11365

больше 6 лет назад

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-11365

больше 6 лет назад

Certain Symfony products are affected by: Incorrect Access Control. Th ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-4423

больше 9 лет назад

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-4423

больше 9 лет назад

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-4423

больше 9 лет назад

The attemptAuthentication function in Component/Security/Http/Firewall ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-2403

больше 8 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-2403

больше 8 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-2403

больше 8 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1902

больше 9 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-1902

больше 9 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-1902

больше 9 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8125

почти 10 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-8125

почти 10 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-8125

почти 10 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8124

почти 10 лет назад

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-8124

почти 10 лет назад

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-8124

почти 10 лет назад

Session fixation vulnerability in the "Remember Me" login feature in S ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-4050

больше 10 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2017-16652

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2 ...

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-11365

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2017-11365

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2017-11365

Certain Symfony products are affected by: Incorrect Access Control. Th ...

CVSS3: 9.8
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall ...

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...

CVSS3: 9.8
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3 ...

CVSS3: 7.5
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in S ...

CVSS2: 6.8
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
76%
Высокий
больше 10 лет назад

Уязвимостей на страницу