zendframework/zendframework1 Security Advisories for 1.12.2 (17)
- 
                        [CRITICAL] Zend Framework SQL injection vector using null byte for PDOPKSA-4bm5-6799-t9s8 CVE-2015-7695 GHSA-2hvh-c5c2-vj85 Affected version: <1.12.16 Reported by: 
 GitHub
- 
                        [MEDIUM] Several Zend Products Vulnerable to XXE and XEE attacksPKSA-7tbc-4p3k-67wb CVE-2014-2683 GHSA-5wm2-38q5-5rxv Affected version: <1.12.4 Reported by: 
 GitHub
- 
                        [MEDIUM] Several Zend Products Vulnerable to XXE and XEE attacksPKSA-7jnn-xn3f-kf8r CVE-2014-2682 GHSA-gp39-h9c2-qw79 Affected version: <1.12.4 Reported by: 
 GitHub
- 
                        [MEDIUM] Several Zend Products Vulnerable to XXE and XEE attacksPKSA-x1xp-mbsx-211w CVE-2014-2681 GHSA-43xg-87xw-jpv8 Affected version: <1.12.4 Reported by: 
 GitHub
- 
                        [MEDIUM] Potential SQL injection in ORDER and GROUP functions of ZF1PKSA-nfx8-h3yx-xf86 GHSA-vvm3-rv48-j3g5 Affected version: <1.12.20 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] Potential SQL injection in ORDER and GROUP statements of Zend_Db_SelectPKSA-8gbh-rfqt-hz91 CVE-2016-6233 GHSA-p9hp-3gpv-52w3 Affected version: <1.12.19 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Potential Insufficient Entropy Vulnerability in ZF1PKSA-pyvt-9h93-zmzx GHSA-229x-22xc-2f2w Affected version: >=1.12.0,<1.12.18 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] Potential Information Disclosure and Insufficient Entropy vulnerability in Zend\Captcha\WordPKSA-vxf6-mhns-kytt GHSA-mhpx-3rv8-wrjm Affected version: >=1.12.0,<1.12.17 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Filesystem Permissions Issues in Multiple ComponentsPKSA-gk48-4tyq-1mz2 CVE-2015-5723 GHSA-pw5c-xqf2-6xc2 Affected version: >=1.12.0,<1.12.16 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] Potential SQL injection vector using null byte for PDO (MsSql, SQLite)PKSA-d2kh-9h2x-yxmw GHSA-2x36-qhx3-7m5f Affected version: >=1.12.0,<1.12.16 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] XXE/XEE vector when using ZendXml on multibyte payloadsPKSA-wkm6-gzx7-1qtv CVE-2015-5161 GHSA-xp8p-9rq5-4wgv Affected version: >=1.12.0,<1.12.14 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Potential CRLF injection attacks in mail and HTTP headersPKSA-t57f-zdqy-25cs CVE-2015-3154 GHSA-5957-5crx-79jx Affected version: >=1.12.0,<1.12.12 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] SQL injection vector when manually quoting values for sqlsrv extension, using null bytePKSA-7r13-9y1m-j63k CVE-2014-8089 GHSA-qh9w-r7g5-q939 Affected version: >=1.12.0,<1.12.9 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Anonymous authentication in ldap_bind() function of PHP, using null bytePKSA-3shc-t8pf-jqw7 CVE-2014-8088 GHSA-f6rc-rh43-h8gr Affected version: >=1.12.0,<1.12.9 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] Potential SQL injection in the ORDER implementation of Zend_Db_SelectPKSA-tvy7-8234-fpzd GHSA-qf36-fx9f-232x Affected version: >=1.12.0,<1.12.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] Potential XXE/XEE attacks using PHP functions: simplexml_load_*, DOMDocument::loadXML, and xml_parsePKSA-6vg5-w5m6-1bx1 GHSA-v42g-7q2x-cw32 Affected version: >=1.12.0,<1.12.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] Potential security issue in login mechanism of ZendOpenId and Zend_OpenId consumerPKSA-vjnw-6878-c6gh GHSA-g52p-86j5-xr8q Affected version: >=1.12.0,<1.12.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories