Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 23

Количество 23

ubuntu логотип

CVE-2025-14177

6 месяцев назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-14177

6 месяцев назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-14177

6 месяцев назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-14177

6 месяцев назад

Information Leak of Memory in getimagesize

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-14177

6 месяцев назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3237-qqm7-mfv7

6 месяцев назад

Information Leak of Memory in getimagesize

EPSS: Низкий
fstec логотип

BDU:2026-02748

7 месяцев назад

Уязвимость функции php_read_stream_all_chunks языка программирования PHP, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 3.7
EPSS: Низкий
redos логотип

ROS-20260514-73-0001

около 1 месяца назад

Уязвимость php

CVSS3: 3.7
EPSS: Низкий
rocky логотип

RLSA-2026:2799

4 месяца назад

Moderate: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2799

4 месяца назад

ELSA-2026-2799: php security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20113-1

5 месяцев назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0086-1

5 месяцев назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0071-1

5 месяцев назад

Security update for php8

EPSS: Низкий
rocky логотип

RLSA-2026:1628

5 месяцев назад

Important: php security update

EPSS: Низкий
rocky логотип

RLSA-2026:1429

5 месяцев назад

Important: php:8.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1628

5 месяцев назад

ELSA-2026-1628: php security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1429

5 месяцев назад

ELSA-2026-1429: php:8.3 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:1412

5 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1409

5 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1412

5 месяцев назад

ELSA-2026-1412: php:8.2 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 3.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-14177

Information Leak of Memory in getimagesize

CVSS3: 3.7
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3237-qqm7-mfv7

Information Leak of Memory in getimagesize

0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-02748

Уязвимость функции php_read_stream_all_chunks языка программирования PHP, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 3.7
0%
Низкий
7 месяцев назад
redos логотип
ROS-20260514-73-0001

Уязвимость php

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:2799

Moderate: php security update

4 месяца назад
oracle-oval логотип
ELSA-2026-2799

ELSA-2026-2799: php security update (MODERATE)

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20113-1

Security update for php8

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0086-1

Security update for php8

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0071-1

Security update for php8

5 месяцев назад
rocky логотип
RLSA-2026:1628

Important: php security update

5 месяцев назад
rocky логотип
RLSA-2026:1429

Important: php:8.3 security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-1628

ELSA-2026-1628: php security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-1429

ELSA-2026-1429: php:8.3 security update (IMPORTANT)

5 месяцев назад
rocky логотип
RLSA-2026:1412

Important: php:8.2 security update

5 месяцев назад
rocky логотип
RLSA-2026:1409

Important: php:8.2 security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-1412

ELSA-2026-1412: php:8.2 security update (IMPORTANT)

5 месяцев назад

Уязвимостей на страницу