Known vulnerabilities in symfony (Debian package) 2.8.7+dfsg-1.3+deb9u1

Vendor: Debian
Version: 2.8.7+dfsg-1.3+deb9u1
Software CPE: cpe:2.3:o:debian:symfony_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 11
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting symfony (Debian package) version 2.8.7+dfsg-1.3+deb9u1 symfony (Debian package) 2.8.7+dfsg-1.3+deb9u1 is affected by 11 vulnerabilities: 3 high, 6 medium, 2 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU22853 - Deserialization of Untrusted Data
CVE-2019-18889
CWE-502 High
No
No
2.8.7+dfsg-1.3+deb9u3, 3.4.22+dfsg-2+deb10u1 19.11.2019 SB2019111915
SB2019111916
SB2019111394
#VU22852 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-18888
CWE-78 Medium
No
No
2.8.7+dfsg-1.3+deb9u3, 3.4.22+dfsg-2+deb10u1 19.11.2019 SB2019111915
SB2019111916
SB2019111392
and 2 more
#VU22851 - Incorrect Comparison
CVE-2019-18887
CWE-697 Medium
No
No
2.8.7+dfsg-1.3+deb9u3, 3.4.22+dfsg-2+deb10u1 19.11.2019 SB2019111915
SB2019111916
SB2019111392
and 2 more
#VU18300 - Improper input validation
CVE-2019-10913
CWE-20 Medium
No
No
2.8.7+dfsg-1.3+deb9u2 18.04.2019 SB2019041802
SB2019051003
SB2019041827
and 7 more
#VU18299 - Deserialization of Untrusted Data
CVE-2019-10912
CWE-502 Medium
No
No
2.8.7+dfsg-1.3+deb9u2 18.04.2019 SB2019041802
SB2019051003
SB2019062507
and 8 more
#VU18298 - Improper Authentication
CVE-2019-10911
CWE-287 Medium
No
No
2.8.7+dfsg-1.3+deb9u2 17.04.2019 SB2019041705
SB2019041802
SB2019051003
and 11 more
#VU18297 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-10910
CWE-94 High
No
No
2.8.7+dfsg-1.3+deb9u2 17.04.2019 SB2019041705
SB2019041802
SB2019051003
and 11 more
#VU18296 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10909
CWE-79 Medium
No
No
2.8.7+dfsg-1.3+deb9u2 17.04.2019 SB2019041705
SB2019041802
SB2019051003
and 11 more
#VU16615 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-19790
CWE-601 Low
No
No
2.8.7+dfsg-1.3+deb9u2 19.12.2018 SB2018121906
SB2019051003
SB2018120740
and 5 more
#VU16614 - Improper input validation
CVE-2018-19789
CWE-20 High
No
No
2.8.7+dfsg-1.3+deb9u2 19.12.2018 SB2018121906
SB2019051003
SB2018120740
and 5 more
#VU14165 - Exposed Dangerous Method or Function
CVE-2018-14773
CWE-749 Low
No
No
2.8.7+dfsg-1.3+deb9u2 01.08.2018 SB2018080118
SB2018080119
SB2019051003