CWE-551

Total CVEs
3
Vulnerabilities
Avg CVSS v3
8.8
High
Avg CVSS v2
7.5
High
Latest CVE
2023
Most Recent

Severity Distribution

Critical 1
33.3%
High 2
66.7%
Medium 0
0%
Low 0
0%

External References

All CVEs (3)

Page 1 of 1
CVSS:9.8(Critical)

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on...

CVSS:8.3(High)

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the...

CVSS:8.3(High)

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request headers to the externa...