Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP HIGH 7.5
CVE-2018-19518EPSS 95%

University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_…

Fix: after 7.2.12
Fix from $1,950 2018-11-25
PHP HIGH 7.5
CVE-2018-19395

ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and application crash…

Fix: after 7.1.24
Fix from $1,950 2018-11-20
PHP HIGH 7.5
CVE-2018-19396

ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call f…

Fix: after 7.1.24
Fix from $1,950 2018-11-20
PHP MEDIUM 6.1
CVE-2018-17082

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-…

Fix: 5.6.38 / 7.0.32+
Fix from $1,600 2018-09-16
PHP HIGH 7.5
CVE-2018-15132EPSS 5%

An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The link…

Fix: 5.6.37 / 7.0.31+
Fix from $1,950 2018-08-07
PHP HIGH 7.5
CVE-2018-14883EPSS 9%

An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-b…

Fix: 5.6.37 / 7.0.31+
Fix from $1,950 2018-08-03
PHP HIGH 7.5
CVE-2018-14884

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a …

Fix: 7.0.27 / 7.1.13+
Fix from $1,950 2018-08-03
PHP MEDIUM 5.5
CVE-2018-14851

exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote…

Fix: 7.0.31 / 7.1.20+
Fix from $1,600 2018-08-02
PHP CRITICAL 9.8
CVE-2017-9120EPSS 8%

PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other…

Fix: 7.4.23 / 8.0.10+
Fix from $2,300 2018-08-02
PHP HIGH 7.5
CVE-2017-9118

PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call.

Fix: 7.4.27 / 8.0.14+
Fix from $1,950 2018-08-02
PHP CRITICAL 9.8
CVE-2018-12882EPSS 7%

exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it cl…

Fix: after 7.2.7
Fix from $2,300 2018-06-26
PHP HIGH 8.8
CVE-2018-10549EPSS 7%

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has…

Fix: 5.6.36 / 7.0.30+
Fix from $1,950 2018-04-29
PHP HIGH 7.5
CVE-2018-10546EPSS 10%

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/…

Fix: 5.6.36 / 7.0.30+
Fix from $1,950 2018-04-29
PHP HIGH 7.5
CVE-2018-10548EPSS 9%

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP se…

Fix: 5.6.36 / 7.0.30+
Fix from $1,950 2018-04-29
PHP MEDIUM 6.1
CVE-2018-10547

An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Re…

Fix: 5.6.36 / 7.0.30+
Fix from $1,600 2018-04-29
PHP CRITICAL 9.8
CVE-2018-7584EPSS 87%

In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an …

Fix: 7.0.28+
Fix from $2,300 2018-03-01
PHP MEDIUM 6.5
CVE-2015-9253

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process i…

Fix: 7.1.20 / 7.2.8+
Fix from $1,600 2018-02-19
PHP HIGH 7.5
CVE-2016-10712

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can …

Fix: after 7.0.2
Fix from $1,950 2018-02-09
PHP MEDIUM 6.1
CVE-2018-5712EPSS 80%

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 40…

Fix: after 7.1.12
Fix from $1,600 2018-01-16
PHP MEDIUM 5.5
CVE-2018-5711EPSS 13%

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, h…

Fix: after 7.1.12
Fix from $1,600 2018-01-16
PHP HIGH 7.5
CVE-2017-16642EPSS 26%

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back …

Fix: 5.6.32 / 7.0.25+
Fix from $1,950 2017-11-07
PHP CRITICAL 9.8
CVE-2017-12932EPSS 7%

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted …

Patch available
Fix from $2,300 2017-08-18
PHP CRITICAL 9.8
CVE-2017-12933EPSS 7%

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a b…

Fix: after 5.6.30
Fix from $2,300 2017-08-18
PHP HIGH 7.5
CVE-2017-12934

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted da…

Mitigation only
Fix from $1,950 2017-08-18
PHP MEDIUM 6.5
CVE-2017-7890

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before …

Fix: after 5.6.30
Fix from $1,600 2017-08-02
PHP HIGH 7.8
CVE-2017-11628

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_pars…

Fix: after 5.6.30
Fix from $1,950 2017-07-25
PHP CRITICAL 9.8
CVE-2017-11362

In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attack…

Mitigation only
Fix from $2,300 2017-07-17
PHP CRITICAL 9.1
CVE-2017-11147

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP in…

Fix: 5.6.30 / 7.0.15+
Fix from $2,300 2017-07-10
PHP HIGH 7.5
CVE-2016-10397

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostn…

Fix: after 5.6.27
Fix from $1,950 2017-07-10
PHP HIGH 7.5
CVE-2017-11142EPSS 8%

In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting…

Fix: after 5.6.30
Fix from $1,950 2017-07-10