dompdf records
4 published records for vendor dompdf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-15 External Control of System or Configuration Setting1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-674 Uncontrolled Recursion1
- CWE-73 External Control of File Name or Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2023-50252No exploit | php-svg-lib unsafe attributes merge when parsing `use` tagdompdf · php-svg-lib · CWE-15 | Critical9.8 | — | 23.9% | Dec 12, 2023 |
39Monitor | CVE-2014-2383Proof of concept | dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and redompdf · dompdf · CWE-200 | Medium6.8 | — | 39.2% | Apr 28, 2014 |
39Monitor | CVE-2024-25117No exploit | php-svg-lib lacks path validation on font through SVG inline stylesphp · php · CWE-73 | Critical9.8 | — | 0.9% | Feb 21, 2024 |
30Monitor | CVE-2023-50251No exploit | php-svg-lib possible DoS caused by infinite recursion when parsing SVG documentdompdf · php-svg-lib · CWE-674 | High7.5 | — | 0.9% | Dec 12, 2023 |
- CVE-2023-5025246Plan
php-svg-lib unsafe attributes merge when parsing `use` tag
CriticalCVSS 9.8No exploitEPSS 24%dompdf · php-svg-libDec 12, 2023
- CVE-2014-238339Monitor
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and re
MediumCVSS 6.8Proof of conceptEPSS 39%dompdf · dompdfApr 28, 2014
- CVE-2024-2511739Monitor
php-svg-lib lacks path validation on font through SVG inline styles
CriticalCVSS 9.8No exploitEPSS 1%php · phpFeb 21, 2024
- CVE-2023-5025130Monitor
php-svg-lib possible DoS caused by infinite recursion when parsing SVG document
HighCVSS 7.5No exploitEPSS 1%dompdf · php-svg-libDec 12, 2023