Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2015-2787EPSS 12% Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5… PHP after 10.6.8 Fix from $1,9502015-03-30 HIGH 7.5 CVE-2015-2331EPSS 28% Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x… PHP after 5.4.38 Fix from $1,9502015-03-30 MEDIUM 5.0 CVE-2015-1352EPSS 8% The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table nam… PHP 5.4.40 / 5.5.24+ Fix from $1,6002015-03-30 HIGH 7.5 CVE-2015-1351EPSS 9% Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote a… PHP 5.5.24 / 5.6.8+ Fix from $1,9502015-03-30 MEDIUM 5.0 CVE-2014-9709EPSS 15% The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a… PHP 5.4.40 / 5.5.21+ Fix from $1,6002015-03-30 HIGH 7.5 CVE-2014-9653 readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider… PHP after 5.21 Fix from $1,9502015-03-30 MEDIUM 5.0 CVE-2014-9652EPSS 5% The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x befo… PHP after 5.20 Fix from $1,6002015-03-30 HIGH 7.5 CVE-2014-9425 Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through … PHP after 10.10.5 Fix from $1,9502014-12-31 MEDIUM 6.5 CVE-2014-0207EPSS 17% The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allo… PHP 5.3.29 / 5.4.30+ Fix from $1,6002014-07-09 MEDIUM 6.5 CVE-2014-3478EPSS 15% Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before … PHP after 5.18 Fix from $1,6002014-07-09 MEDIUM 6.5 CVE-2014-3480EPSS 11% The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not p… PHP 5.3.29 / 5.4.30+ Fix from $1,6002014-07-09 MEDIUM 5.0 CVE-2014-3538EPSS 12% file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service… PHP 5.4.32 / 5.5.16+ Fix from $1,6002014-07-03 MEDIUM 5.1 CVE-2014-4049EPSS 11% Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of… PHP 5.3.29 / 5.4.30+ Fix from $1,6002014-06-18 MEDIUM 5.0 CVE-2013-7345 The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitio… PHP 5.4.27 / 5.5.11+ Fix from $1,6002014-03-24 MEDIUM 5.0 CVE-2014-1943EPSS 5% Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a cra… PHP 5.4.26 / 5.5.10+ Fix from $1,6002014-02-18 HIGH 7.5 CVE-2013-6420EPSS 36% The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (… PHP after 10.9.1 Fix from $1,9502013-12-17 MEDIUM 5.0 CVE-2013-6712 The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might… PHP 5.3.29 / 5.4.24+ Fix from $1,6002013-11-28 CRITICAL 9.8 CVE-2012-1823 KEVEPSS 100% sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query string… PHP 5.3.12 / 5.4.2+ Fix from $2,3002012-05-11 MEDIUM 5.0 CVE-2011-2483 crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-… PHP 1.1 / 5.3.7+ Fix from $1,6002011-08-25 CRITICAL 9.8 CVE-2010-1866EPSS 7% The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of s… PHP after 5.3.2 Fix from $2,3002010-05-07 MEDIUM 5.0 CVE-2009-4017EPSS 12% PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, wh… PHP 5.2.12+ Fix from $1,6002009-11-24 HIGH 9.3 CVE-2009-3546EPSS 10% The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colors… PHP Patch available Fix from $1,9502009-10-19 HIGH 7.5 CVE-2008-2371EPSS 7% Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause… PHP after 5.2.7 Fix from $1,9502008-07-07 CRITICAL 9.8 CVE-2008-2108 The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a port… PHP 4.4.8 / 5.2.5+ Fix from $2,3002008-05-07 CRITICAL 9.8 CVE-2008-0599EPSS 11% The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length … PHP 5.2.6 / 10.5.4+ Fix from $2,3002008-05-05 HIGH 7.5 CVE-2008-0373 Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files. F1 Maxs File Uploader Mitigation only Fix from $1,9502008-01-22 MEDIUM 5.0 CVE-2007-6512 PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob… Mysql Banner Exchange Mitigation only Fix from $1,6002007-12-21 MEDIUM 5.0 CVE-2007-5128 SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date paramete… PHP after 5.0.0 Fix from $1,6002007-09-27 MEDIUM 6.8 CVE-2007-4889 The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (… Mysql Extension after 5.2.4 Fix from $1,6002007-09-14 HIGH 7.5 CVE-2007-4596EPSS 8% The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eva… PHP No fix yet Fix from $1,9502007-08-30