CVEs (724)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Php2Php Storage Automation StoreNov 21, 2024 Aug 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This...Show more |
2Netapp Php2Php Storage Automation StoreNov 21, 2024 Aug 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Aug 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c. |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Aug 2, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and applica...Show more |
2Netapp Php2Php Storage Automation StoreNov 21, 2024 Aug 2, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real...Show more |
2Netapp Php2Php Storage Automation StoreNov 21, 2024 Aug 2, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call. |
3Canonical NetappPhp3Php Storage Automation StoreUbuntu LinuxNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable co...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and applic...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a r...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multiby...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPA...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Mar 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standa...Show more |
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthr...Show more |
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = strea...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Jan 16, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file. |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Jan 16, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a cra...Show more |
4Canonical DebianNetapp+1 more5Clustered Data Ontap Debian LinuxPhp+2 moreMay 13, 2026 Nov 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings t...Show more |
ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploit...Show more |
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of thi...Show more |