Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP CRITICAL 9.8
CVE-2016-4344EPSS 5%

Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl…

Fix: 7.0.4+
Fix from $2,300 2016-05-22
PHP HIGH 8.8
CVE-2016-4343

The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which al…

Fix: 5.5.36 / 5.6.18+
Fix from $1,950 2016-05-22
PHP CRITICAL 9.8
CVE-2015-8880

Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.

Mitigation only
Fix from $2,300 2016-05-22
PHP HIGH 7.5
CVE-2015-8877

The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses incons…

Fix: after 5.6.11
Fix from $1,950 2016-05-22
PHP CRITICAL 9.6
CVE-2015-8866

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader…

Fix: 5.5.22 / 5.6.6+
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4073EPSS 7%

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x bef…

Fix: after 10.11.3
Fix from $2,300 2016-05-20
PHP CRITICAL 9.8
CVE-2016-4072EPSS 6%

The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted fi…

Fix: after 10.11.4
Fix from $2,300 2016-05-20
PHP CRITICAL 9.8
CVE-2016-4071EPSS 19%

Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows …

Fix: after 10.11.4
Fix from $2,300 2016-05-20
PHP HIGH 7.3
CVE-2015-8865EPSS 5%

The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x befo…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
PHP CRITICAL 9.8
CVE-2016-2554EPSS 11%

Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a deni…

Fix: after 5.5.31
Fix from $2,300 2016-05-16
PHP HIGH 7.5
CVE-2015-6838EPSS 7%

The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before …

Fix: after 2.9.1
Fix from $1,950 2016-05-16
PHP HIGH 7.5
CVE-2015-6837EPSS 7%

The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before …

Fix: after 2.9.1
Fix from $1,950 2016-05-16
PHP CRITICAL 9.8
CVE-2015-4643EPSS 17%

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP se…

Fix: 5.4.42 / 5.5.26+
Fix from $2,300 2016-05-16
PHP HIGH 7.5
CVE-2015-4605EPSS 7%

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, d…

Fix: after 5.4.39
Fix from $1,950 2016-05-16
PHP HIGH 7.5
CVE-2015-4604EPSS 7%

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, do…

Fix: after 5.4.39
Fix from $1,950 2016-05-16
PHP CRITICAL 9.8
CVE-2015-4603EPSS 11%

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote at…

Fix: after 5.4.39
Fix from $2,300 2016-05-16
PHP CRITICAL 9.8
CVE-2015-4599EPSS 11%

The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obta…

Fix: after 5.4.39
Fix from $2,300 2016-05-16
PHP MEDIUM 5.3
CVE-2015-3412

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …

Fix: after 5.4.39
Fix from $1,600 2016-05-16
PHP HIGH 8.2
CVE-2016-3142EPSS 5%

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensiti…

Fix: after 10.11.4
Fix from $1,950 2016-03-31
PHP CRITICAL 9.8
CVE-2016-3141EPSS 36%

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial o…

Fix: after 10.11.4
Fix from $2,300 2016-03-31
PHP HIGH 7.3
CVE-2016-1904

Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspec…

Patch available
Fix from $1,950 2016-01-19
PHP CRITICAL 9.8
CVE-2015-8617EPSS 23%

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute…

Patch available
Fix from $2,300 2016-01-19
PHP HIGH 8.6
CVE-2015-8616

Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote at…

No fix yet
Fix from $1,950 2016-01-19
PHP HIGH 7.3
CVE-2015-6527

The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a craf…

No fix yet
Fix from $1,950 2016-01-19
PHP CRITICAL 9.8
CVE-2016-1283EPSS 8%

The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'…

Fix: 5.6.32 / 7.0.25+
Fix from $2,300 2016-01-03
PHP MEDIUM 6.8
CVE-2015-7804EPSS 9%

Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a…

Fix: after 10.11.1
Fix from $1,600 2015-12-11
PHP MEDIUM 6.8
CVE-2015-7803EPSS 10%

The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service…

Fix: after 10.11.1
Fix from $1,600 2015-12-11
PHP CRITICAL 9.8
CVE-2015-8394

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overfl…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
PHP HIGH 7.5
CVE-2015-4025EPSS 20%

PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which a…

Fix: after 5.4.40
Fix from $1,950 2015-06-09
PHP MEDIUM 5.8
CVE-2015-2783EPSS 11%

ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from proces…

Fix: after 5.4.39
Fix from $1,600 2015-06-09