Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2015-2787EPSS 12%
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5…
PHP
after 10.6.8
HIGH 7.5
CVE-2015-2331EPSS 28%
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x…
PHP
after 5.4.38
MEDIUM 5.0
CVE-2015-1352EPSS 8%
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table nam…
PHP
5.4.40 / 5.5.24+
HIGH 7.5
CVE-2015-1351EPSS 9%
Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote a…
PHP
5.5.24 / 5.6.8+
MEDIUM 5.0
CVE-2014-9709EPSS 15%
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a…
PHP
5.4.40 / 5.5.21+
HIGH 7.5
CVE-2014-9653
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider…
PHP
after 5.21
MEDIUM 5.0
CVE-2014-9652EPSS 5%
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x befo…
PHP
after 5.20
HIGH 7.5
CVE-2014-9425
Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through …
PHP
after 10.10.5
MEDIUM 6.5
CVE-2014-0207EPSS 17%
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allo…
PHP
5.3.29 / 5.4.30+
MEDIUM 6.5
CVE-2014-3478EPSS 15%
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before …
PHP
after 5.18
MEDIUM 6.5
CVE-2014-3480EPSS 11%
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not p…
PHP
5.3.29 / 5.4.30+
MEDIUM 5.0
CVE-2014-3538EPSS 12%
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service…
PHP
5.4.32 / 5.5.16+
MEDIUM 5.1
CVE-2014-4049EPSS 11%
Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of…
PHP
5.3.29 / 5.4.30+
MEDIUM 5.0
CVE-2013-7345
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitio…
PHP
5.4.27 / 5.5.11+
MEDIUM 5.0
CVE-2014-1943EPSS 5%
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a cra…
PHP
5.4.26 / 5.5.10+
HIGH 7.5
CVE-2013-6420EPSS 36%
The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (…
PHP
after 10.9.1
MEDIUM 5.0
CVE-2013-6712
The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might…
PHP
5.3.29 / 5.4.24+
CRITICAL 9.8
CVE-2012-1823 KEVEPSS 100%
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query string…
PHP
5.3.12 / 5.4.2+
MEDIUM 5.0
CVE-2011-2483
crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-…
PHP
1.1 / 5.3.7+
CRITICAL 9.8
CVE-2010-1866EPSS 7%
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of s…
PHP
after 5.3.2
MEDIUM 5.0
CVE-2009-4017EPSS 12%
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, wh…
PHP
5.2.12+
HIGH 9.3
CVE-2009-3546EPSS 10%
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colors…
PHP
Patch available
HIGH 7.5
CVE-2008-2371EPSS 7%
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause…
PHP
after 5.2.7
CRITICAL 9.8
CVE-2008-2108
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a port…
PHP
4.4.8 / 5.2.5+
CRITICAL 9.8
CVE-2008-0599EPSS 11%
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length …
PHP
5.2.6 / 10.5.4+
HIGH 7.5
CVE-2008-0373
Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files.
F1 Maxs File Uploader
Mitigation only
MEDIUM 5.0
CVE-2007-6512
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…
Mysql Banner Exchange
Mitigation only
MEDIUM 5.0
CVE-2007-5128
SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date paramete…
PHP
after 5.0.0
MEDIUM 6.8
CVE-2007-4889
The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (…
Mysql Extension
after 5.2.4
HIGH 7.5
CVE-2007-4596EPSS 8%
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eva…
PHP
No fix yet