Vulnerabilities > Zend > Zend Framework > 2.4.10

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2020-29312 Deserialization of Untrusted Data vulnerability in Zend Framework
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function.
network
low complexity
zend CWE-502
critical
9.8
2016-12-30 CVE-2016-10034 Command Injection vulnerability in Zend Framework
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
network
low complexity
zend CWE-77
critical
9.8