Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

PHP HIGH 7.5
CVE-2017-12934

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted da…

Mitigation only
Fix from $1,950 2017-08-18
PHP CRITICAL 9.8
CVE-2017-11362

In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attack…

Mitigation only
Fix from $2,300 2017-07-17
Pear HIGH 7.5
CVE-2017-5630EPSS 13%

PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which al…

No fix yet
Fix from $1,950 2017-02-01
PHP CRITICAL 9.8
CVE-2016-7479EPSS 42%

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free.…

No fix yet
Fix from $2,300 2017-01-12
PHP CRITICAL 9.8
CVE-2015-8880

Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.

Mitigation only
Fix from $2,300 2016-05-22
PHP HIGH 8.6
CVE-2015-8616

Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote at…

No fix yet
Fix from $1,950 2016-01-19
PHP HIGH 7.3
CVE-2015-6527

The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a craf…

No fix yet
Fix from $1,950 2016-01-19
F1 Maxs File Uploader HIGH 7.5
CVE-2008-0373

Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files.

Mitigation only
Fix from $1,950 2008-01-22
Mysql Banner Exchange MEDIUM 5.0
CVE-2007-6512

PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…

Mitigation only
Fix from $1,600 2007-12-21
PHP HIGH 7.5
CVE-2007-4596EPSS 8%

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eva…

No fix yet
Fix from $1,950 2007-08-30
PHP HIGH 7.5
CVE-2007-4033EPSS 19%

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary …

No fix yet
Fix from $1,950 2007-07-27
PHP MEDIUM 5.0
CVE-2007-3205

The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwri…

Mitigation only
Fix from $1,600 2007-06-13
PHP MEDIUM 5.0
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the m…

No fix yet
Fix from $1,600 2007-05-16
Com Extensions MEDIUM 6.8
CVE-2007-1382

The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demo…

No fix yet
Fix from $1,600 2007-03-10
PHP HIGH 7.5
CVE-2007-0909

Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of…

Mitigation only
Fix from $1,950 2007-02-13
Ar Memberscript HIGH 7.5
CVE-2006-6590

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,950 2006-12-15
Bloq HIGH 7.5
CVE-2006-6592

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] par…

Mitigation only
Fix from $1,950 2006-12-15
Blog Cms HIGH 7.5
CVE-2006-6552

PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2006-12-14
Animated Smiley Generator HIGH 7.5
CVE-2006-6541

PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2006-12-14
Errordocs HIGH 7.5
CVE-2006-6545

PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attack…

No fix yet
Fix from $1,950 2006-12-14
Php Script Index HIGH 7.5
CVE-2006-1559

SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provena…

Mitigation only
Fix from $1,950 2006-03-31
Php Script Index MEDIUM 6.8
CVE-2006-1558

Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the sea…

No fix yet
Fix from $1,600 2006-03-31
Php Fi MEDIUM 5.0
CVE-1999-0346

CGI PHP mlog script allows an attacker to read any file on the target server.

Mitigation only
Fix from $1,600 1997-10-16