CVE-2014-4914: Debian Linux

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Zend Zend Framework: before 1.12.7 (fixed in 1.12.7)

Published 2017-12-29. Last modified 2026-06-17.