Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP HIGH 7.5
CVE-2017-11144EPSS 6%

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check the return value of the OpenSSL…

Fix: after 5.6.30
Fix from $1,950 2017-07-10
PHP HIGH 7.5
CVE-2017-11145

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by atta…

Fix: after 5.6.30
Fix from $1,950 2017-07-10
PHP CRITICAL 9.8
CVE-2016-4473EPSS 8%

/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to C…

Patch available
Fix from $2,300 2017-06-08
PHP CRITICAL 9.8
CVE-2017-9224EPSS 7%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r…

Fix: 5.6.31 / 7.0.21+
Fix from $2,300 2017-05-24
PHP CRITICAL 9.8
CVE-2017-9225

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds w…

Fix: after 7.1.5
Fix from $2,300 2017-05-24
PHP CRITICAL 9.8
CVE-2017-9226EPSS 8%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wr…

Fix: 5.6.31 / 7.0.21+
Fix from $2,300 2017-05-24
PHP CRITICAL 9.8
CVE-2017-9227EPSS 6%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r…

Fix: 5.6.31 / 7.0.21+
Fix from $2,300 2017-05-24
PHP CRITICAL 9.8
CVE-2017-9228EPSS 6%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wr…

Fix: 5.6.31 / 7.0.21+
Fix from $2,300 2017-05-24
PHP HIGH 7.5
CVE-2017-9229EPSS 5%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in lef…

Fix: 5.6.31 / 7.0.21+
Fix from $1,950 2017-05-24
PHP CRITICAL 9.8
CVE-2017-9119

The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application …

Patch available
Fix from $2,300 2017-05-21
PHP HIGH 7.0
CVE-2017-9067

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insuffic…

Patch available
Fix from $1,950 2017-05-18
PHP CRITICAL 9.8
CVE-2017-8923EPSS 7%

The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative lengt…

Fix: 7.4.24 / 8.0.11+
Fix from $2,300 2017-05-12
PHP HIGH 7.8
CVE-2016-5399EPSS 10%

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of ser…

Fix: 5.6.24 / 7.0.9+
Fix from $1,950 2017-04-21
PHP HIGH 7.5
CVE-2017-7963

The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption…

Fix: after 7.1.4
Fix from $1,950 2017-04-19
PHP HIGH 7.5
CVE-2017-6441

The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and applicat…

Patch available
Fix from $1,950 2017-04-03
PHP HIGH 7.4
CVE-2017-7272

PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port …

Fix: after 7.1.3
Fix from $1,950 2017-03-27
PHP HIGH 7.5
CVE-2015-8994

An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28…

Fix: 7.0.14+
Fix from $1,950 2017-03-02
Pear HIGH 7.5
CVE-2017-5630EPSS 13%

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al…

No fix yet
Fix from $1,950 2017-02-01
PHP CRITICAL 9.8
CVE-2016-10160EPSS 7%

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause…

Fix: 5.6.30 / 7.0.15+
Fix from $2,300 2017-01-24
PHP HIGH 7.5
CVE-2016-10158EPSS 8%

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to …

Fix: after 5.6.29
Fix from $1,950 2017-01-24
PHP HIGH 7.5
CVE-2016-10159EPSS 8%

Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause…

Fix: 7.0.15+
Fix from $1,950 2017-01-24
PHP HIGH 7.5
CVE-2016-10161EPSS 13%

The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attack…

Fix: after 5.6.29
Fix from $1,950 2017-01-24
PHP HIGH 7.5
CVE-2016-10162EPSS 6%

The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,950 2017-01-24
Pecl Http CRITICAL 9.8
CVE-2016-5873

Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable …

Fix: after 3.0.1
Fix from $2,300 2017-01-23
PHP CRITICAL 9.8
CVE-2016-7479EPSS 42%

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.…

No fix yet
Fix from $2,300 2017-01-12
PHP CRITICAL 9.8
CVE-2016-7480EPSS 42%

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows …

Fix: 7.0.11+
Fix from $2,300 2017-01-11
PHP CRITICAL 9.8
CVE-2017-5340EPSS 17%

Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attac…

Fix: 7.0.15 / 7.1.1+
Fix from $2,300 2017-01-11
PHP CRITICAL 9.8
CVE-2016-9137EPSS 5%

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attacker…

Fix: after 5.6.26
Fix from $2,300 2017-01-04
PHP CRITICAL 9.8
CVE-2016-9138

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denia…

Fix: after 5.6.27
Fix from $2,300 2017-01-04
PHP CRITICAL 9.8
CVE-2016-9935EPSS 7%

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service…

Fix: after 5.6.28
Fix from $2,300 2017-01-04