Package impact

php Packagist / symfony/security-core

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2016-2403 critical 9.8 9.8 9y ago Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. debianphp
CVE-2016-1902 high 7.5 7.5 10y ago The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the par… debianphp