
CVE-2020-29312
https://notcve.org/view.php?id=CVE-2020-29312
04 Apr 2023 — An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020. • http://zend.com • CWE-502: Deserialization of Untrusted Data •

CVE-2021-3007
https://notcve.org/view.php?id=CVE-2021-3007
04 Jan 2021 — Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cas... • https://github.com/Vulnmachines/ZF3_CVE-2021-3007 • CWE-502: Deserialization of Untrusted Data •

CVE-2015-5723 – Debian Security Advisory 3369-1
https://notcve.org/view.php?id=CVE-2015-5723
07 Oct 2015 — Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code. Doctrine Annotations en versiones anteriores a 1.2.7, Cach... • http://framework.zend.com/security/advisory/ZF2015-07 • CWE-264: Permissions, Privileges, and Access Controls •