Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2016-4344EPSS 5% Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl… PHP 7.0.4+ Fix from $2,3002016-05-22 HIGH 8.8 CVE-2016-4343 The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which al… PHP 5.5.36 / 5.6.18+ Fix from $1,9502016-05-22 CRITICAL 9.8 CVE-2015-8880 Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error. PHP Mitigation only Fix from $2,3002016-05-22 HIGH 7.5 CVE-2015-8877 The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses incons… PHP after 5.6.11 Fix from $1,9502016-05-22 CRITICAL 9.6 CVE-2015-8866 ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader… PHP 5.5.22 / 5.6.6+ Fix from $2,3002016-05-22 CRITICAL 9.8 CVE-2016-4073EPSS 7% Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x bef… PHP after 10.11.3 Fix from $2,3002016-05-20 CRITICAL 9.8 CVE-2016-4072EPSS 6% The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted fi… PHP after 10.11.4 Fix from $2,3002016-05-20 CRITICAL 9.8 CVE-2016-4071EPSS 19% Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows … PHP after 10.11.4 Fix from $2,3002016-05-20 HIGH 7.3 CVE-2015-8865EPSS 5% The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x befo… PHP after 10.11.4 Fix from $1,9502016-05-20 CRITICAL 9.8 CVE-2016-2554EPSS 11% Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a deni… PHP after 5.5.31 Fix from $2,3002016-05-16 HIGH 7.5 CVE-2015-6838EPSS 7% The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before … PHP after 2.9.1 Fix from $1,9502016-05-16 HIGH 7.5 CVE-2015-6837EPSS 7% The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before … PHP after 2.9.1 Fix from $1,9502016-05-16 CRITICAL 9.8 CVE-2015-4643EPSS 17% Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP se… PHP 5.4.42 / 5.5.26+ Fix from $2,3002016-05-16 HIGH 7.5 CVE-2015-4605EPSS 7% The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, d… PHP after 5.4.39 Fix from $1,9502016-05-16 HIGH 7.5 CVE-2015-4604EPSS 7% The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, do… PHP after 5.4.39 Fix from $1,9502016-05-16 CRITICAL 9.8 CVE-2015-4603EPSS 11% The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote at… PHP after 5.4.39 Fix from $2,3002016-05-16 CRITICAL 9.8 CVE-2015-4599EPSS 11% The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obta… PHP after 5.4.39 Fix from $2,3002016-05-16 MEDIUM 5.3 CVE-2015-3412 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers … PHP after 5.4.39 Fix from $1,6002016-05-16 HIGH 8.2 CVE-2016-3142EPSS 5% The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensiti… PHP after 10.11.4 Fix from $1,9502016-03-31 CRITICAL 9.8 CVE-2016-3141EPSS 36% Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial o… PHP after 10.11.4 Fix from $2,3002016-03-31 HIGH 7.3 CVE-2016-1904 Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspec… PHP Patch available Fix from $1,9502016-01-19 CRITICAL 9.8 CVE-2015-8617EPSS 23% Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute… PHP Patch available Fix from $2,3002016-01-19 HIGH 8.6 CVE-2015-8616 Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote at… PHP No fix yet Fix from $1,9502016-01-19 HIGH 7.3 CVE-2015-6527 The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a craf… PHP No fix yet Fix from $1,9502016-01-19 CRITICAL 9.8 CVE-2016-1283EPSS 8% The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'… PHP 5.6.32 / 7.0.25+ Fix from $2,3002016-01-03 MEDIUM 6.8 CVE-2015-7804EPSS 9% Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a… PHP after 10.11.1 Fix from $1,6002015-12-11 MEDIUM 6.8 CVE-2015-7803EPSS 10% The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service… PHP after 10.11.1 Fix from $1,6002015-12-11 CRITICAL 9.8 CVE-2015-8394 PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overfl… PHP 5.5.32 / 5.6.18+ Fix from $2,3002015-12-02 HIGH 7.5 CVE-2015-4025EPSS 20% PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which a… PHP after 5.4.40 Fix from $1,9502015-06-09 MEDIUM 5.8 CVE-2015-2783EPSS 11% ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from proces… PHP after 5.4.39 Fix from $1,6002015-06-09