Количество 378
Количество 378
GHSA-h7vf-5wrv-9fhv
Symfony storing cookie headers in HttpCache
GHSA-h5x3-xfc9-m39h
Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
GHSA-h5vq-qfcg-4m6p
Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
GHSA-g97c-jfx6-xvxh
Symfony Vulnerable to Timing Attack
GHSA-g4rg-rw65-8hfg
Symfony Session Fixation Vulnerability
GHSA-g4m9-5hpf-hx72
Firewall configured with unanimous strategy was not actually unanimous in Symfony
GHSA-g4g7-q726-v5hg
Symfony CSRF Token Fixation
GHSA-fqc7-9xjw-jrh3
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
GHSA-cr49-fx2v-9p57
Symfony Denial of Service Via Long Password Hashing
GHSA-cqqh-94r6-wjrg
Symfony SSRF Vulnerability via Form Component
GHSA-c49r-8gj6-768r
Symfony Directory Traversal
GHSA-c2p3-7m5p-cv8x
Symfony hardened the parser when handling untrusted input
GHSA-9j54-wmcm-g7mf
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."
GHSA-9frc-8383-795m
Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
GHSA-92x6-h2gr-8gxq
Symfony CSRF Vulnerability
GHSA-8v8v-g73j-492j
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
GHSA-89r2-5g34-2g47
Symfony Open Redirect
GHSA-89cp-fvcc-hxh7
Symfony Access Control Vulnerability
GHSA-83c3-qx27-2rwr
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
GHSA-7w53-hfpw-rg3g
Symfony Arbitrary PHP code Execution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h7vf-5wrv-9fhv Symfony storing cookie headers in HttpCache | CVSS3: 5.9 | 4% Низкий | больше 3 лет назад | |
GHSA-h5x3-xfc9-m39h Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization | 0% Низкий | около 2 месяцев назад | ||
GHSA-h5vq-qfcg-4m6p Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing | 0% Низкий | 2 месяца назад | ||
GHSA-g97c-jfx6-xvxh Symfony Vulnerable to Timing Attack | 3% Низкий | около 4 лет назад | ||
GHSA-g4rg-rw65-8hfg Symfony Session Fixation Vulnerability | CVSS3: 8.1 | 2% Низкий | около 4 лет назад | |
GHSA-g4m9-5hpf-hx72 Firewall configured with unanimous strategy was not actually unanimous in Symfony | CVSS3: 7.6 | 1% Низкий | больше 6 лет назад | |
GHSA-g4g7-q726-v5hg Symfony CSRF Token Fixation | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-fqc7-9xjw-jrh3 SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch | 0% Низкий | около 2 месяцев назад | ||
GHSA-cr49-fx2v-9p57 Symfony Denial of Service Via Long Password Hashing | 2% Низкий | около 4 лет назад | ||
GHSA-cqqh-94r6-wjrg Symfony SSRF Vulnerability via Form Component | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-c49r-8gj6-768r Symfony Directory Traversal | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-c2p3-7m5p-cv8x Symfony hardened the parser when handling untrusted input | 1% Низкий | 2 месяца назад | ||
GHSA-9j54-wmcm-g7mf Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes." | 1% Низкий | около 4 лет назад | ||
GHSA-9frc-8383-795m Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex | 1% Низкий | 2 месяца назад | ||
GHSA-92x6-h2gr-8gxq Symfony CSRF Vulnerability | CVSS3: 5.9 | 1% Низкий | около 4 лет назад | |
GHSA-8v8v-g73j-492j Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS | 1% Низкий | 2 месяца назад | ||
GHSA-89r2-5g34-2g47 Symfony Open Redirect | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-89cp-fvcc-hxh7 Symfony Access Control Vulnerability | 1% Низкий | около 4 лет назад | ||
GHSA-83c3-qx27-2rwr Symfony Allows URI Restrictions Bypass Via Double-Encoded String | 2% Низкий | около 4 лет назад | ||
GHSA-7w53-hfpw-rg3g Symfony Arbitrary PHP code Execution | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу