Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP CRITICAL 9.8
CVE-2019-11043 KEVEPSS 99%

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modu…

Fix: 7.1.33 / 7.2.24+
Fix from $2,300 2019-10-28
Ext Http CRITICAL 9.8
CVE-2016-7398EPSS 7%

A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well…

Fix: after 3.0.1
Fix from $2,300 2019-09-06
PHP HIGH 7.1
CVE-2019-11041

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x belo…

Fix: 5.19.0 / 7.1.31+
Fix from $1,950 2019-08-09
PHP HIGH 7.1
CVE-2019-11042

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x belo…

Fix: 5.19.0 / 7.1.31+
Fix from $1,950 2019-08-09
PHP HIGH 7.5
CVE-2017-7189

main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the add…

Fix: 7.0.16+
Fix from $1,950 2019-07-10
PHP CRITICAL 9.8
CVE-2019-13224

A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service,…

Fix: 7.1.32 / 7.2.23+
Fix from $2,300 2019-07-10
PHP CRITICAL 9.1
CVE-2019-11039

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due …

Fix: 7.1.30 / 7.2.19+
Fix from $2,300 2019-06-19
PHP CRITICAL 9.1
CVE-2019-11040

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x belo…

Fix: 7.1.30 / 7.2.19+
Fix from $2,300 2019-06-19
PHP MEDIUM 5.3
CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x be…

Fix: 7.1.30 / 7.2.19+
Fix from $1,600 2019-06-19
Imagick CRITICAL 9.8
CVE-2019-11037

In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check tha…

Fix: after 3.4.4
Fix from $2,300 2019-05-03
PHP CRITICAL 9.1
CVE-2019-11036EPSS 7%

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past…

Fix: 7.1.29 / 7.2.18+
Fix from $2,300 2019-05-03
PHP CRITICAL 9.1
CVE-2019-11034

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past…

Fix: 7.1.28 / 7.2.17+
Fix from $2,300 2019-04-18
PHP CRITICAL 9.1
CVE-2019-11035

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past…

Fix: 7.1.28 / 7.2.17+
Fix from $2,300 2019-04-18
PHP HIGH 8.1
CVE-2019-9675EPSS 6%

An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long…

Fix: 7.1.27 / 7.3.3+
Fix from $1,950 2019-03-11
PHP CRITICAL 9.8
CVE-2019-9641EPSS 9%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex…

Fix: 7.1.27 / 7.2.16+
Fix from $2,300 2019-03-09
PHP HIGH 7.5
CVE-2019-9637EPSS 7%

An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented,…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
PHP HIGH 7.5
CVE-2019-9638EPSS 7%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
PHP HIGH 7.5
CVE-2019-9639EPSS 8%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
PHP HIGH 7.5
CVE-2019-9640EPSS 6%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_pro…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
PHP CRITICAL 9.8
CVE-2019-9020EPSS 10%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_de…

Fix: 5.6.40 / 7.1.26+
Fix from $2,300 2019-02-22
PHP CRITICAL 9.8
CVE-2019-9021EPSS 10%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR r…

Fix: 5.6.40 / 7.1.26+
Fix from $2,300 2019-02-22
PHP CRITICAL 9.8
CVE-2019-9023EPSS 9%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read…

Fix: 5.6.40 / 7.1.26+
Fix from $2,300 2019-02-22
PHP CRITICAL 9.8
CVE-2019-9025

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php…

Fix: 7.3.1+
Fix from $2,300 2019-02-22
PHP HIGH 7.5
CVE-2019-9022

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can all…

Fix: 7.1.26 / 7.2.14+
Fix from $1,950 2019-02-22
PHP HIGH 7.5
CVE-2019-9024EPSS 7%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XML…

Fix: 5.6.40 / 7.1.26+
Fix from $1,950 2019-02-22
PHP HIGH 7.5
CVE-2018-20783EPSS 6%

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an atta…

Fix: 5.6.39 / 7.0.33+
Fix from $1,950 2019-02-21
PHP HIGH 8.8
CVE-2019-6977EPSS 64%

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x…

Fix: 5.6.40 / 7.1.26+
Fix from $1,950 2019-01-27
Pear Archive Tar HIGH 8.8
CVE-2018-1000888EPSS 19%

PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with…

Fix: after 1.4.3
Fix from $1,950 2018-12-28
PHP HIGH 7.5
CVE-2018-19935EPSS 6%

ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application cr…

Fix: 5.6.39 / 7.0.33+
Fix from $1,950 2018-12-07
PHP HIGH 8.8
CVE-2018-19520

An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain …

Fix: after 5.6.38
Fix from $1,950 2018-11-25