Brian Sweeney
10 exploits
Active since Apr 2022
dompdf < 1.2.1 - Remote Code Execution via CSS @font-face src:url
CVSS 9.8
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
dompdf < 2.0.0 - Remote Code Execution via PHAR Deserialization
CVSS 9.8
dompdf < 2.0.0 - XML External Entity Injection via SVG Parser
CVSS 9.8
dompdf < 2.0.0 - Path Traversal via Untrusted File Path
CVSS 5.3
Dompdf <2.0.3 - Arbitrary URL Fetch via SVG href Parsing
CVSS 10.0
php-svg-lib <0.5.1 - Memory Corruption
CVSS 5.3
php-svg-lib < 0.5.1 - PHAR Deserialization via Unsanitized href Attribute in SVG use Tag
CVSS 8.3
dompdf < 2.0.4 - Uncontrolled Recursion via Chained SVG Image References
CVSS 5.3
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8