← Back

CVE-2015-5161

nvd nist
Published: Aug 25, 2015Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

Affected (154)

Products: Zend: Zend Framework
1 product
Zend Framework
Configuration A
154 vulnerable
Vulnerable SoftwareAffected Versions
Zend
Version 1.0.0
Version 1.0.0 rc1
Version 1.0.0 rc2
Version 1.0.0 rc2a
Version 1.0.0 rc3
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.10.0
Version 1.10.0 alpha1
Version 1.10.0 beta1
Version 1.10.0 rc1
Version 1.10.1
Version 1.10.2
Version 1.10.3
Version 1.10.4
Version 1.10.5
Version 1.10.6
Version 1.10.7
Version 1.10.8
Version 1.10.9
Version 1.11.0
Version 1.11.0 b1
Version 1.11.0 rc1
Version 1.11.10
Version 1.11.11
Version 1.11.12
Version 1.11.13
Version 1.11.1
Version 1.11.2
Version 1.11.3
Version 1.11.4
Version 1.11.5
Version 1.11.6
Version 1.11.7
Version 1.11.8
Version 1.11.9
Version 1.12.0
Version 1.12.0 rc1
Version 1.12.0 rc2
Version 1.12.0 rc3
Version 1.12.0 rc4
Version 1.12.10
Version 1.12.11
Version 1.12.12
Version 1.12.13
Version 1.12.1
Version 1.12.2
Version 1.12.3
Version 1.12.4
Version 1.12.5
Version 1.12.6
Version 1.12.7
Version 1.12.8
Version 1.12.9
Version 1.5.0 rc1
Version 1.5.0 rc2
Version 1.5.0 rc3
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.6.0
Version 1.6.0 rc1
Version 1.6.0 rc2
Version 1.6.0 rc3
Version 1.6.1
Version 1.6.2
Version 1.7.0
Version 1.7.0 pl1
Version 1.7.0 pr
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.3 pl1
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7.7
Version 1.7.8
Version 1.7.9
Version 1.8.0
Version 1.8.0 a1
Version 1.8.0 b1
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.4 pl1
Version 1.8.5
Version 1.9.0
Version 1.9.0 a1
Version 1.9.0 b1
Version 1.9.0 rc1
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.3 pl1
Version 1.9.4
Version 1.9.5
Version 1.9.6
Version 1.9.7
Version 1.9.8
Version 2.0.0
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.0 rc4
Version 2.0.0 rc5
Version 2.0.0 rc6
Version 2.0.0 rc7
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.1.0
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.2.0
Version 2.2.10
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2.9
Version 2.3.0
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.4.0
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.5
Version 2.5.0
Version 2.5.1

References (20)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Exploit
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.