CVEs (724)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject OraclePcre+1 more4Fedora LinuxPerl Compatible Regular Expression Library+1 moreMay 6, 2026 Dec 2, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other imp...Show more |
3Fedoraproject PcrePhp3Fedora Perl Compatible Regular Expression LibraryPhpMay 6, 2026 Dec 2, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as...Show more |
3Apple PhpRedhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive informat...Show more |
3Apple PhpRedhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary co...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension res...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and ac...Show more |
5Apple HpOracle+2 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+9 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, lead...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of se...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted len...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspe...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly h...Show more |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or poss...Show more |
4Apple OpensusePhp+1 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via...Show more |
4Apple OpensusePhp+1 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attac...Show more |
5Debian FedoraprojectNih+2 more5Debian Linux FedoraLibzip+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remot...Show more |
5Canonical DebianOpensuse+2 more5Debian Linux OpensusePhp+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent att...Show more |