Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP HIGH 7.5
CVE-2015-2787EPSS 12%

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5…

Fix: after 10.6.8
Fix from $1,950 2015-03-30
PHP HIGH 7.5
CVE-2015-2331EPSS 28%

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x…

Fix: after 5.4.38
Fix from $1,950 2015-03-30
PHP MEDIUM 5.0
CVE-2015-1352EPSS 8%

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table nam…

Fix: 5.4.40 / 5.5.24+
Fix from $1,600 2015-03-30
PHP HIGH 7.5
CVE-2015-1351EPSS 9%

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote a…

Fix: 5.5.24 / 5.6.8+
Fix from $1,950 2015-03-30
PHP MEDIUM 5.0
CVE-2014-9709EPSS 15%

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a…

Fix: 5.4.40 / 5.5.21+
Fix from $1,600 2015-03-30
PHP HIGH 7.5
CVE-2014-9653

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider…

Fix: after 5.21
Fix from $1,950 2015-03-30
PHP MEDIUM 5.0
CVE-2014-9652EPSS 5%

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x befo…

Fix: after 5.20
Fix from $1,600 2015-03-30
PHP HIGH 7.5
CVE-2014-9425

Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through …

Fix: after 10.10.5
Fix from $1,950 2014-12-31
PHP MEDIUM 6.5
CVE-2014-0207EPSS 17%

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allo…

Fix: 5.3.29 / 5.4.30+
Fix from $1,600 2014-07-09
PHP MEDIUM 6.5
CVE-2014-3478EPSS 15%

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before …

Fix: after 5.18
Fix from $1,600 2014-07-09
PHP MEDIUM 6.5
CVE-2014-3480EPSS 11%

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not p…

Fix: 5.3.29 / 5.4.30+
Fix from $1,600 2014-07-09
PHP MEDIUM 5.0
CVE-2014-3538EPSS 12%

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service…

Fix: 5.4.32 / 5.5.16+
Fix from $1,600 2014-07-03
PHP MEDIUM 5.1
CVE-2014-4049EPSS 11%

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of…

Fix: 5.3.29 / 5.4.30+
Fix from $1,600 2014-06-18
PHP MEDIUM 5.0
CVE-2013-7345

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitio…

Fix: 5.4.27 / 5.5.11+
Fix from $1,600 2014-03-24
PHP MEDIUM 5.0
CVE-2014-1943EPSS 5%

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a cra…

Fix: 5.4.26 / 5.5.10+
Fix from $1,600 2014-02-18
PHP HIGH 7.5
CVE-2013-6420EPSS 36%

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (…

Fix: after 10.9.1
Fix from $1,950 2013-12-17
PHP MEDIUM 5.0
CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might…

Fix: 5.3.29 / 5.4.24+
Fix from $1,600 2013-11-28
PHP CRITICAL 9.8
CVE-2012-1823 KEVEPSS 100%

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query string…

Fix: 5.3.12 / 5.4.2+
Fix from $2,300 2012-05-11
PHP MEDIUM 5.0
CVE-2011-2483

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-…

Fix: 1.1 / 5.3.7+
Fix from $1,600 2011-08-25
PHP CRITICAL 9.8
CVE-2010-1866EPSS 7%

The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of s…

Fix: after 5.3.2
Fix from $2,300 2010-05-07
PHP MEDIUM 5.0
CVE-2009-4017EPSS 12%

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, wh…

Fix: 5.2.12+
Fix from $1,600 2009-11-24
PHP HIGH 9.3
CVE-2009-3546EPSS 10%

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colors…

Patch available
Fix from $1,950 2009-10-19
PHP HIGH 7.5
CVE-2008-2371EPSS 7%

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause…

Fix: after 5.2.7
Fix from $1,950 2008-07-07
PHP CRITICAL 9.8
CVE-2008-2108

The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a port…

Fix: 4.4.8 / 5.2.5+
Fix from $2,300 2008-05-07
PHP CRITICAL 9.8
CVE-2008-0599EPSS 11%

The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length …

Fix: 5.2.6 / 10.5.4+
Fix from $2,300 2008-05-05
F1 Maxs File Uploader HIGH 7.5
CVE-2008-0373

Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files.

Mitigation only
Fix from $1,950 2008-01-22
Mysql Banner Exchange MEDIUM 5.0
CVE-2007-6512

PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…

Mitigation only
Fix from $1,600 2007-12-21
PHP MEDIUM 5.0
CVE-2007-5128

SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date paramete…

Fix: after 5.0.0
Fix from $1,600 2007-09-27
Mysql Extension MEDIUM 6.8
CVE-2007-4889

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (…

Fix: after 5.2.4
Fix from $1,600 2007-09-14
PHP HIGH 7.5
CVE-2007-4596EPSS 8%

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eva…

No fix yet
Fix from $1,950 2007-08-30