Количество 31
Количество 31
GHSA-7jrw-539f-x6vr
ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
CVE-2026-14355
ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-14355
In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...
SUSE-SU-2026:3165-1
Security update for php7
ROS-20260902-80-0029
Уязвимость php 8.5
ROS-20260902-80-0028
Уязвимость php 8.4
ROS-20260902-80-0027
Уязвимость php 8.3
ROS-20260902-80-0026
Уязвимость php
ROS-20260902-73-0027
Уязвимость php 8.4
ROS-20260902-73-0026
Уязвимость php 8.3
ROS-20260902-73-0025
Уязвимость php
RLSA-2026:49914
Low: php8.4 security, bug fix, and enhancement update
RLSA-2026:48197
Low: php:8.3 security, bug fix, and enhancement update
RLSA-2026:48170
Low: php security, bug fix, and enhancement update
RLSA-2026:47750
Low: php:7.4 security, bug fix, and enhancement update
RLSA-2026:47749
Low: php:8.2 security, bug fix, and enhancement update
RLSA-2026:40416
Low: php:8.2 security, bug fix, and enhancement update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7jrw-539f-x6vr ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD | CVSS3: 4.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort. | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ... | CVSS3: 5.6 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:3165-1 Security update for php7 | 0% Низкий | около 2 месяцев назад | ||
ROS-20260902-80-0029 Уязвимость php 8.5 | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
ROS-20260902-80-0028 Уязвимость php 8.4 | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
ROS-20260902-80-0027 Уязвимость php 8.3 | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
ROS-20260902-80-0026 Уязвимость php | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
ROS-20260902-73-0027 Уязвимость php 8.4 | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
ROS-20260902-73-0026 Уязвимость php 8.3 | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
ROS-20260902-73-0025 Уязвимость php | CVSS3: 5.3 | 0% Низкий | 13 дней назад | |
RLSA-2026:49914 Low: php8.4 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:48197 Low: php:8.3 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:48170 Low: php security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:47750 Low: php:7.4 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:47749 Low: php:8.2 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:40416 Low: php:8.2 security, bug fix, and enhancement update | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу