Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2017-11144EPSS 6%
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check the return value of the OpenSSL…
PHP
after 5.6.30
HIGH 7.5
CVE-2017-11145
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by atta…
PHP
after 5.6.30
CRITICAL 9.8
CVE-2016-4473EPSS 8%
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to C…
PHP
Patch available
CRITICAL 9.8
CVE-2017-9224EPSS 7%
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r…
PHP
5.6.31 / 7.0.21+
CRITICAL 9.8
CVE-2017-9225
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds w…
PHP
after 7.1.5
CRITICAL 9.8
CVE-2017-9226EPSS 8%
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wr…
PHP
5.6.31 / 7.0.21+
CRITICAL 9.8
CVE-2017-9227EPSS 6%
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r…
PHP
5.6.31 / 7.0.21+
CRITICAL 9.8
CVE-2017-9228EPSS 6%
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wr…
PHP
5.6.31 / 7.0.21+
HIGH 7.5
CVE-2017-9229EPSS 5%
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in lef…
PHP
5.6.31 / 7.0.21+
CRITICAL 9.8
CVE-2017-9119
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application …
PHP
Patch available
HIGH 7.0
CVE-2017-9067
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insuffic…
PHP
Patch available
CRITICAL 9.8
CVE-2017-8923EPSS 7%
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative lengt…
PHP
7.4.24 / 8.0.11+
HIGH 7.8
CVE-2016-5399EPSS 10%
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of ser…
PHP
5.6.24 / 7.0.9+
HIGH 7.5
CVE-2017-7963
The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption…
PHP
after 7.1.4
HIGH 7.5
CVE-2017-6441
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and applicat…
PHP
Patch available
HIGH 7.4
CVE-2017-7272
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port …
PHP
after 7.1.3
HIGH 7.5
CVE-2015-8994
An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28…
PHP
7.0.14+
HIGH 7.5
CVE-2017-5630EPSS 13%
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al…
Pear
No fix yet
CRITICAL 9.8
CVE-2016-10160EPSS 7%
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause…
PHP
5.6.30 / 7.0.15+
HIGH 7.5
CVE-2016-10158EPSS 8%
The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to …
PHP
after 5.6.29
HIGH 7.5
CVE-2016-10159EPSS 8%
Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause…
PHP
7.0.15+
HIGH 7.5
CVE-2016-10161EPSS 13%
The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attack…
PHP
after 5.6.29
HIGH 7.5
CVE-2016-10162EPSS 6%
The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of s…
PHP
Patch available
CRITICAL 9.8
CVE-2016-5873
Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable …
Pecl Http
after 3.0.1
CRITICAL 9.8
CVE-2016-7479EPSS 42%
In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.…
PHP
No fix yet
CRITICAL 9.8
CVE-2016-7480EPSS 42%
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows …
PHP
7.0.11+
CRITICAL 9.8
CVE-2017-5340EPSS 17%
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attac…
PHP
7.0.15 / 7.1.1+
CRITICAL 9.8
CVE-2016-9137EPSS 5%
Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attacker…
PHP
after 5.6.26
CRITICAL 9.8
CVE-2016-9138
PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denia…
PHP
after 5.6.27
CRITICAL 9.8
CVE-2016-9935EPSS 7%
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service…
PHP
after 5.6.28