Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-11144EPSS 6% In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check the return value of the OpenSSL… PHP after 5.6.30 Fix from $1,9502017-07-10 HIGH 7.5 CVE-2017-11145 In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by atta… PHP after 5.6.30 Fix from $1,9502017-07-10 CRITICAL 9.8 CVE-2016-4473EPSS 8% /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to C… PHP Patch available Fix from $2,3002017-06-08 CRITICAL 9.8 CVE-2017-9224EPSS 7% An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r… PHP 5.6.31 / 7.0.21+ Fix from $2,3002017-05-24 CRITICAL 9.8 CVE-2017-9225 An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds w… PHP after 7.1.5 Fix from $2,3002017-05-24 CRITICAL 9.8 CVE-2017-9226EPSS 8% An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wr… PHP 5.6.31 / 7.0.21+ Fix from $2,3002017-05-24 CRITICAL 9.8 CVE-2017-9227EPSS 6% An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r… PHP 5.6.31 / 7.0.21+ Fix from $2,3002017-05-24 CRITICAL 9.8 CVE-2017-9228EPSS 6% An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds wr… PHP 5.6.31 / 7.0.21+ Fix from $2,3002017-05-24 HIGH 7.5 CVE-2017-9229EPSS 5% An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in lef… PHP 5.6.31 / 7.0.21+ Fix from $1,9502017-05-24 CRITICAL 9.8 CVE-2017-9119 The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application … PHP Patch available Fix from $2,3002017-05-21 HIGH 7.0 CVE-2017-9067 In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insuffic… PHP Patch available Fix from $1,9502017-05-18 CRITICAL 9.8 CVE-2017-8923EPSS 7% The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative lengt… PHP 7.4.24 / 8.0.11+ Fix from $2,3002017-05-12 HIGH 7.8 CVE-2016-5399EPSS 10% The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of ser… PHP 5.6.24 / 7.0.9+ Fix from $1,9502017-04-21 HIGH 7.5 CVE-2017-7963 The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption… PHP after 7.1.4 Fix from $1,9502017-04-19 HIGH 7.5 CVE-2017-6441 The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and applicat… PHP Patch available Fix from $1,9502017-04-03 HIGH 7.4 CVE-2017-7272 PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port … PHP after 7.1.3 Fix from $1,9502017-03-27 HIGH 7.5 CVE-2015-8994 An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28… PHP 7.0.14+ Fix from $1,9502017-03-02 HIGH 7.5 CVE-2017-5630EPSS 13% PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al… Pear No fix yet Fix from $1,9502017-02-01 CRITICAL 9.8 CVE-2016-10160EPSS 7% Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause… PHP 5.6.30 / 7.0.15+ Fix from $2,3002017-01-24 HIGH 7.5 CVE-2016-10158EPSS 8% The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to … PHP after 5.6.29 Fix from $1,9502017-01-24 HIGH 7.5 CVE-2016-10159EPSS 8% Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause… PHP 7.0.15+ Fix from $1,9502017-01-24 HIGH 7.5 CVE-2016-10161EPSS 13% The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attack… PHP after 5.6.29 Fix from $1,9502017-01-24 HIGH 7.5 CVE-2016-10162EPSS 6% The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of s… PHP Patch available Fix from $1,9502017-01-24 CRITICAL 9.8 CVE-2016-5873 Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable … Pecl Http after 3.0.1 Fix from $2,3002017-01-23 CRITICAL 9.8 CVE-2016-7479EPSS 42% In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.… PHP No fix yet Fix from $2,3002017-01-12 CRITICAL 9.8 CVE-2016-7480EPSS 42% The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows … PHP 7.0.11+ Fix from $2,3002017-01-11 CRITICAL 9.8 CVE-2017-5340EPSS 17% Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attac… PHP 7.0.15 / 7.1.1+ Fix from $2,3002017-01-11 CRITICAL 9.8 CVE-2016-9137EPSS 5% Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attacker… PHP after 5.6.26 Fix from $2,3002017-01-04 CRITICAL 9.8 CVE-2016-9138 PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denia… PHP after 5.6.27 Fix from $2,3002017-01-04 CRITICAL 9.8 CVE-2016-9935EPSS 7% The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service… PHP after 5.6.28 Fix from $2,3002017-01-04