Skip to content
Noroxi

pear records

22 published records for vendor pear.

All records

22 records
  • Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows re

    CriticalCVSS 10.0No exploitEPSS 6%

    pear · pearNov 29, 2009

  • Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to e

    CriticalCVSS 10.0No exploitEPSS 6%

    pear · pearNov 29, 2009

  • PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.

    CriticalCVSS 9.8No exploitEPSS 5%

    pear · html ajaxFeb 6, 2017

  • Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nu

    CriticalCVSS 10.0No exploitEPSS 1%

    pear · text passwordDec 31, 2005

  • PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpoint

    CriticalCVSS 9.3No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails

    CriticalCVSS 9.2No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validation

    CriticalCVSS 9.2No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • PEAR Has a Predictable Verification Hash in Election Account Requests

    HighCVSS 8.2No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filename

    HighCVSS 8.2No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • CVE-2006-0868
    31Monitor

    Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4

    HighCVSS 7.5No exploitEPSS 3%

    pear · xml rpcFeb 23, 2006

  • CVE-2009-4023
    31Monitor

    Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for

    HighCVSS 7.5No exploitEPSS 2%

    pear · pearNov 29, 2009

  • PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug

    HighCVSS 7.1No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • CVE-2009-4111
    27Monitor

    Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remot

    MediumCVSS 6.8No exploitEPSS 2%

    pear · mailNov 29, 2009

  • PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filter

    MediumCVSS 6.9No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitution

    MediumCVSS 6.9No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • CVE-2006-0869
    26Monitor

    Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0

    MediumCVSS 6.4Proof of conceptEPSS 4%

    pear · pear liveuserFeb 23, 2006

  • CVE-2006-0931
    21Monitor

    Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite

    MediumCVSS 5.0No exploitEPSS 2%

    pear · pear archive tarFeb 28, 2006

  • CVE-2006-0932
    21Monitor

    Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files

    MediumCVSS 5.0No exploitEPSS 2%

    pear · pear archive zipFeb 28, 2006

  • The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environment

    MediumCVSS 5.3No exploitEPSS 1%

    pear · crypt gpgFeb 17, 2022

  • PEAR is Vulnerable to SQL Injection in Category Deletion

    MediumCVSS 5.3No exploitEPSS 0%

    pear · pearwebFeb 3, 2026

  • CVE-2007-3628
    20Monitor

    Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers t

    MediumCVSS 5.0No exploitEPSS 1%

    pear · structures datagrid datasource mdb2Jul 9, 2007

  • CVE-2007-5934
    17Monitor

    The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents

    MediumCVSS 4.3No exploitEPSS 2%

    pear · structures datagrid datasource mdb2Nov 13, 2007