Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-11043 KEVEPSS 99% In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modu… PHP 7.1.33 / 7.2.24+ Fix from $2,3002019-10-28 CRITICAL 9.8 CVE-2016-7398EPSS 7% A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well… Ext Http after 3.0.1 Fix from $2,3002019-09-06 HIGH 7.1 CVE-2019-11041 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x belo… PHP 5.19.0 / 7.1.31+ Fix from $1,9502019-08-09 HIGH 7.1 CVE-2019-11042 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x belo… PHP 5.19.0 / 7.1.31+ Fix from $1,9502019-08-09 HIGH 7.5 CVE-2017-7189 main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the add… PHP 7.0.16+ Fix from $1,9502019-07-10 CRITICAL 9.8 CVE-2019-13224 A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service,… PHP 7.1.32 / 7.2.23+ Fix from $2,3002019-07-10 CRITICAL 9.1 CVE-2019-11039 Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due … PHP 7.1.30 / 7.2.19+ Fix from $2,3002019-06-19 CRITICAL 9.1 CVE-2019-11040 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x belo… PHP 7.1.30 / 7.2.19+ Fix from $2,3002019-06-19 MEDIUM 5.3 CVE-2019-11038 When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x be… PHP 7.1.30 / 7.2.19+ Fix from $1,6002019-06-19 CRITICAL 9.8 CVE-2019-11037 In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix() function did not check tha… Imagick after 3.4.4 Fix from $2,3002019-05-03 CRITICAL 9.1 CVE-2019-11036EPSS 7% When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past… PHP 7.1.29 / 7.2.18+ Fix from $2,3002019-05-03 CRITICAL 9.1 CVE-2019-11034 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past… PHP 7.1.28 / 7.2.17+ Fix from $2,3002019-04-18 CRITICAL 9.1 CVE-2019-11035 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past… PHP 7.1.28 / 7.2.17+ Fix from $2,3002019-04-18 HIGH 8.1 CVE-2019-9675EPSS 6% An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long… PHP 7.1.27 / 7.3.3+ Fix from $1,9502019-03-11 CRITICAL 9.8 CVE-2019-9641EPSS 9% An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex… PHP 7.1.27 / 7.2.16+ Fix from $2,3002019-03-09 HIGH 7.5 CVE-2019-9637EPSS 7% An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented,… PHP 7.1.27 / 7.2.16+ Fix from $1,9502019-03-09 HIGH 7.5 CVE-2019-9638EPSS 7% An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex… PHP 7.1.27 / 7.2.16+ Fix from $1,9502019-03-09 HIGH 7.5 CVE-2019-9639EPSS 8% An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex… PHP 7.1.27 / 7.2.16+ Fix from $1,9502019-03-09 HIGH 7.5 CVE-2019-9640EPSS 6% An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_pro… PHP 7.1.27 / 7.2.16+ Fix from $1,9502019-03-09 CRITICAL 9.8 CVE-2019-9020EPSS 10% An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_de… PHP 5.6.40 / 7.1.26+ Fix from $2,3002019-02-22 CRITICAL 9.8 CVE-2019-9021EPSS 10% An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR r… PHP 5.6.40 / 7.1.26+ Fix from $2,3002019-02-22 CRITICAL 9.8 CVE-2019-9023EPSS 9% An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read… PHP 5.6.40 / 7.1.26+ Fix from $2,3002019-02-22 CRITICAL 9.8 CVE-2019-9025 An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php… PHP 7.3.1+ Fix from $2,3002019-02-22 HIGH 7.5 CVE-2019-9022 An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can all… PHP 7.1.26 / 7.2.14+ Fix from $1,9502019-02-22 HIGH 7.5 CVE-2019-9024EPSS 7% An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XML… PHP 5.6.40 / 7.1.26+ Fix from $1,9502019-02-22 HIGH 7.5 CVE-2018-20783EPSS 6% In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an atta… PHP 5.6.39 / 7.0.33+ Fix from $1,9502019-02-21 HIGH 8.8 CVE-2019-6977EPSS 64% gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x… PHP 5.6.40 / 7.1.26+ Fix from $1,9502019-01-27 HIGH 8.8 CVE-2018-1000888EPSS 19% PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with… Pear Archive Tar after 1.4.3 Fix from $1,9502018-12-28 HIGH 7.5 CVE-2018-19935EPSS 6% ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application cr… PHP 5.6.39 / 7.0.33+ Fix from $1,9502018-12-07 HIGH 8.8 CVE-2018-19520 An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain … PHP after 5.6.38 Fix from $1,9502018-11-25