Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 378

Количество 378

nvd логотип

CVE-2016-4423

около 10 лет назад

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-4423

около 10 лет назад

The attemptAuthentication function in Component/Security/Http/Firewall ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-2403

больше 9 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-2403

больше 9 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-2403

больше 9 лет назад

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1902

около 10 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-1902

около 10 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-1902

около 10 лет назад

The nextBytes function in the SecureRandom class in Symfony before 2.3 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8125

больше 10 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-8125

больше 10 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-8125

больше 10 лет назад

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8124

больше 10 лет назад

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-8124

больше 10 лет назад

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-8124

больше 10 лет назад

Session fixation vulnerability in the "Remember Me" login feature in S ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-4050

около 11 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-4050

около 11 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-4050

около 11 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-2308

около 11 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2308

около 11 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2308

около 11 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in S ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS3: 7.5
2%
Низкий
около 10 лет назад
debian логотип
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall ...

CVSS3: 7.5
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
3%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS3: 9.8
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2403

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...

CVSS3: 9.8
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
2%
Низкий
около 10 лет назад
debian логотип
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3 ...

CVSS3: 7.5
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS2: 7.5
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-8125

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...

CVSS2: 7.5
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-8124

Session fixation vulnerability in the "Remember Me" login feature in S ...

CVSS2: 6.8
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
8%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
8%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through ...

CVSS2: 4.3
8%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
1%
Низкий
около 11 лет назад
debian логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in S ...

CVSS2: 6.8
1%
Низкий
около 11 лет назад

Уязвимостей на страницу