CVE Browser
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Dompdf: Chroot Validation Bypass
Dompdf: File existence oracle via font-face stylesheet declaration
Improper Restriction of XML External Entity Reference in dompdf/dompdf
PHAR Deserialization in dompdf/dompdf
php-svg-lib lacks path validation on font through SVG inline styles
Dompdf possible DoS caused by infinite recursion when parsing SVG images
php-svg-lib unsafe attributes merge when parsing `use` tag
php-svg-lib possible DoS caused by infinite recursion when parsing SVG document
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
URI validation failure on SVG parsing in Dompdf
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demons…
External Control of File Name or Path in dompdf/dompdf
Server-Side Request Forgery (SSRF) in dompdf/dompdf
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input fi…
DOMPDF before 0.6.2 allows Information Disclosure.
DOMPDF before 0.6.2 allows denial of service.
DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files…
Showing 1 to 22 CVEs · page 1