Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-12934 ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted da… PHP Mitigation only Fix from $1,9502017-08-18 CRITICAL 9.8 CVE-2017-11362 In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attack… PHP Mitigation only Fix from $2,3002017-07-17 HIGH 7.5 CVE-2017-5630EPSS 13% PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al… Pear No fix yet Fix from $1,9502017-02-01 CRITICAL 9.8 CVE-2016-7479EPSS 42% In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.… PHP No fix yet Fix from $2,3002017-01-12 CRITICAL 9.8 CVE-2015-8880 Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error. PHP Mitigation only Fix from $2,3002016-05-22 HIGH 8.6 CVE-2015-8616 Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote at… PHP No fix yet Fix from $1,9502016-01-19 HIGH 7.3 CVE-2015-6527 The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a craf… PHP No fix yet Fix from $1,9502016-01-19 HIGH 7.5 CVE-2008-0373 Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files. F1 Maxs File Uploader Mitigation only Fix from $1,9502008-01-22 MEDIUM 5.0 CVE-2007-6512 PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob… Mysql Banner Exchange Mitigation only Fix from $1,6002007-12-21 HIGH 7.5 CVE-2007-4596EPSS 8% The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eva… PHP No fix yet Fix from $1,9502007-08-30 HIGH 7.5 CVE-2007-4033EPSS 19% Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary … PHP No fix yet Fix from $1,9502007-07-27 MEDIUM 5.0 CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwri… PHP Mitigation only Fix from $1,6002007-06-13 MEDIUM 5.0 CVE-2007-2728 The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the m… PHP No fix yet Fix from $1,6002007-05-16 MEDIUM 6.8 CVE-2007-1382 The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demo… Com Extensions No fix yet Fix from $1,6002007-03-10 HIGH 7.5 CVE-2007-0909 Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of… PHP Mitigation only Fix from $1,9502007-02-13 HIGH 7.5 CVE-2006-6590 PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the … Ar Memberscript No fix yet Fix from $1,9502006-12-15 HIGH 7.5 CVE-2006-6592 Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] par… Bloq Mitigation only Fix from $1,9502006-12-15 HIGH 7.5 CVE-2006-6552 PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrar… Blog Cms No fix yet Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-6541 PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute ar… Animated Smiley Generator Mitigation only Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-6545 PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attack… Errordocs No fix yet Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-1559 SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provena… Php Script Index Mitigation only Fix from $1,9502006-03-31 MEDIUM 6.8 CVE-2006-1558 Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the sea… Php Script Index No fix yet Fix from $1,6002006-03-31 MEDIUM 5.0 CVE-1999-0346 CGI PHP mlog script allows an attacker to read any file on the target server. Php Fi Mitigation only Fix from $1,6001997-10-16