Search CVE reports


Toggle filters

11 – 19 of 19 results


CVE-2023-23924

Medium priority
Not affected

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar`...

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2022-41343

Medium priority
Not affected

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2022-2400

Medium priority

Some fixes available 4 of 23

External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.

3 affected packages

icingaweb2, civicrm, php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icingaweb2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
civicrm Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
php-dompdf Not in release Not in release Fixed Fixed Fixed
Show less packages

CVE-2022-0085

Medium priority
Ignored

Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2022-28368

Medium priority
Ignored

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2014-5013

Medium priority

Some fixes available 1 of 5

DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2014-5012

Low priority

Some fixes available 1 of 5

DOMPDF before 0.6.2 allows denial of service.

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2014-5011

Low priority

Some fixes available 1 of 5

DOMPDF before 0.6.2 allows Information Disclosure.

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected Not affected Not affected
Show less packages

CVE-2014-2383

Medium priority
Not affected

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as...

1 affected package

php-dompdf

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-dompdf Not affected
Show less packages