Логотип exploitDog
bind:"CVE-2021-32610" OR bind:"CVE-2021-21707" OR bind:"CVE-2021-21708"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-32610" OR bind:"CVE-2021-21707" OR bind:"CVE-2021-21708"

Количество 58

Количество 58

rocky логотип

RLSA-2022:7628

почти 3 года назад

Moderate: php:7.4 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7628

почти 3 года назад

ELSA-2022-7628: php:7.4 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-32610

больше 4 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2021-32610

больше 4 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2021-32610

больше 4 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2021-32610

больше 4 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3198-2

больше 2 лет назад

Security update for php8-pear

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3198-1

около 3 лет назад

Security update for php8-pear

EPSS: Низкий
github логотип

GHSA-p8q8-jfcv-g2h2

около 4 лет назад

Directory Traversal in Archive_Tar

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2021-05771

больше 4 лет назад

Уязвимость пакета Archive_Tar библиотеки PHP классов PEAR CMS-системы Drupal, позволяющая нарушителю оказать влияние на целостность, доступность и конфиденциальность данных

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3997-1

почти 3 года назад

Security update for php7

EPSS: Низкий
ubuntu логотип

CVE-2021-21707

почти 4 года назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2021-21707

почти 4 года назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-21707

почти 4 года назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-21707

около 1 месяца назад

Special characters break path parsing in XML functions

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-21707

почти 4 года назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-21708

больше 3 лет назад

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2021-21708

больше 3 лет назад

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2021-21708

больше 3 лет назад

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2021-21708

около 1 месяца назад

UAF due to php_filter_float() failing

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2022:7628

Moderate: php:7.4 security, bug fix, and enhancement update

почти 3 года назад
oracle-oval логотип
ELSA-2022-7628

ELSA-2022-7628: php:7.4 security, bug fix, and enhancement update (MODERATE)

почти 3 года назад
ubuntu логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.4
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ...

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:3198-2

Security update for php8-pear

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3198-1

Security update for php8-pear

1%
Низкий
около 3 лет назад
github логотип
GHSA-p8q8-jfcv-g2h2

Directory Traversal in Archive_Tar

CVSS3: 7.1
1%
Низкий
около 4 лет назад
fstec логотип
BDU:2021-05771

Уязвимость пакета Archive_Tar библиотеки PHP классов PEAR CMS-системы Drupal, позволяющая нарушителю оказать влияние на целостность, доступность и конфиденциальность данных

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:3997-1

Security update for php7

почти 3 года назад
ubuntu логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-21707

Special characters break path parsing in XML functions

CVSS3: 5.3
1%
Низкий
около 1 месяца назад
debian логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below ...

CVSS3: 5.3
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2021-21708

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-21708

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-21708

In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2021-21708

UAF due to php_filter_float() failing

CVSS3: 8.2
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу