The (1) order and (2) group methods in ZendDbSelect in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
Last updated 25 August 2025
A heap-buffer overflow vulnerability was discovered in cryptopp. This vulnerability can be used to remotely gain access to shell.
References:
http://seclists.org/oss-sec/2016/q4/760 https://pony7.fr/ctf:public:32c3:cryptmsg
Upstream bug:
https://github.com/dlitz/pycrypto/issues/176
Potential SQL injection in ORDER and GROUP statements of ZendDbSelect