Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2016-4344EPSS 5%
Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl…
PHP
7.0.4+
HIGH 8.8
CVE-2016-4343
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which al…
PHP
5.5.36 / 5.6.18+
CRITICAL 9.8
CVE-2015-8880
Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.
PHP
Mitigation only
HIGH 7.5
CVE-2015-8877
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses incons…
PHP
after 5.6.11
CRITICAL 9.6
CVE-2015-8866
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader…
PHP
5.5.22 / 5.6.6+
CRITICAL 9.8
CVE-2016-4073EPSS 7%
Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x bef…
PHP
after 10.11.3
CRITICAL 9.8
CVE-2016-4072EPSS 6%
The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted fi…
PHP
after 10.11.4
CRITICAL 9.8
CVE-2016-4071EPSS 19%
Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows …
PHP
after 10.11.4
HIGH 7.3
CVE-2015-8865EPSS 5%
The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x befo…
PHP
after 10.11.4
CRITICAL 9.8
CVE-2016-2554EPSS 11%
Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a deni…
PHP
after 5.5.31
HIGH 7.5
CVE-2015-6838EPSS 7%
The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before …
PHP
after 2.9.1
HIGH 7.5
CVE-2015-6837EPSS 7%
The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before …
PHP
after 2.9.1
CRITICAL 9.8
CVE-2015-4643EPSS 17%
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP se…
PHP
5.4.42 / 5.5.26+
HIGH 7.5
CVE-2015-4605EPSS 7%
The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, d…
PHP
after 5.4.39
HIGH 7.5
CVE-2015-4604EPSS 7%
The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, do…
PHP
after 5.4.39
CRITICAL 9.8
CVE-2015-4603EPSS 11%
The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote at…
PHP
after 5.4.39
CRITICAL 9.8
CVE-2015-4599EPSS 11%
The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obta…
PHP
after 5.4.39
MEDIUM 5.3
CVE-2015-3412
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …
PHP
after 5.4.39
HIGH 8.2
CVE-2016-3142EPSS 5%
The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensiti…
PHP
after 10.11.4
CRITICAL 9.8
CVE-2016-3141EPSS 36%
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial o…
PHP
after 10.11.4
HIGH 7.3
CVE-2016-1904
Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspec…
PHP
Patch available
CRITICAL 9.8
CVE-2015-8617EPSS 23%
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute…
PHP
Patch available
HIGH 8.6
CVE-2015-8616
Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote at…
PHP
No fix yet
HIGH 7.3
CVE-2015-6527
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a craf…
PHP
No fix yet
CRITICAL 9.8
CVE-2016-1283EPSS 8%
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'…
PHP
5.6.32 / 7.0.25+
MEDIUM 6.8
CVE-2015-7804EPSS 9%
Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a…
PHP
after 10.11.1
MEDIUM 6.8
CVE-2015-7803EPSS 10%
The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service…
PHP
after 10.11.1
CRITICAL 9.8
CVE-2015-8394
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overfl…
PHP
5.5.32 / 5.6.18+
HIGH 7.5
CVE-2015-4025EPSS 20%
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which a…
PHP
after 5.4.40
MEDIUM 5.8
CVE-2015-2783EPSS 11%
ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from proces…
PHP
after 5.4.39