Known Vulnerabilities for products from Pear

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Pear".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-24953 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.3 - MEDIUM 2022-02-17 2023-08-08
CVE-2017-5677 json PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code exec... 9.8 - CRITICAL 2017-02-06 2019-10-03
CVE-2009-4111 json Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PE... Not Provided 2009-11-29 2026-04-23
CVE-2009-4025 json Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for... Not Provided 2009-11-29 2026-04-23
CVE-2009-4024 json Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote... Not Provided 2009-11-29 2026-04-23
CVE-2009-4023 json Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail pack... Not Provided 2009-11-29 2026-04-23
CVE-2007-5934 json The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and sto... Not Provided 2007-11-13 2026-04-23
CVE-2007-3628 json Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier all... Not Provided 2007-07-09 2026-04-23
CVE-2006-0932 json Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite a... Not Provided 2006-02-28 2025-04-03
CVE-2006-0931 json Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to creat... Not Provided 2006-02-28 2025-04-03
CVE-2006-0869 json Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (P... Not Provided 2006-02-23 2025-04-03
CVE-2006-0868 json Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x... Not Provided 2006-02-23 2025-04-03
CVE-2005-4730 json Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" o... Not Provided 2005-12-31 2025-04-03

Known software with vulnerabilities from Pear

Type Vendor Product Version
ApplicationPearHtml Ajax0.1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report