Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 33

Количество 33

github логотип

GHSA-85c2-q967-79q5

5 месяцев назад

Use-After-Free in SOAP using Apache map with Remote Code Execution

EPSS: Низкий
ubuntu логотип

CVE-2026-6722

5 месяцев назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-6722

5 месяцев назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2026-6722

5 месяцев назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2026-6722

4 месяца назад

Use-After-Free in SOAP using Apache map

EPSS: Низкий
debian логотип

CVE-2026-6722

5 месяцев назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-06622

5 месяцев назад

Уязвимость функции soap_add_xml_ref() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-80-0007

около 1 месяца назад

Уязвимость php 8.5

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-80-0006

около 1 месяца назад

Уязвимость php 8.4

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-80-0005

около 1 месяца назад

Уязвимость php 8.3

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-80-0004

около 1 месяца назад

Уязвимость php

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-73-0006

около 1 месяца назад

Уязвимость php 8.4

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-73-0005

около 1 месяца назад

Уязвимость php 8.3

CVSS3: 9
EPSS: Низкий
redos логотип

ROS-20260831-73-0004

около 1 месяца назад

Уязвимость php

CVSS3: 9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2091-1

4 месяца назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2026:34354

3 месяца назад

Important: php:7.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-34354

3 месяца назад

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:33449

2 месяца назад

Important: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-33449

3 месяца назад

ELSA-2026-33449: php security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

5 месяцев назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-85c2-q967-79q5

Use-After-Free in SOAP using Apache map with Remote Code Execution

1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 7.7
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-6722

Use-After-Free in SOAP using Apache map

1%
Низкий
4 месяца назад
debian логотип
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 9.8
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-06622

Уязвимость функции soap_add_xml_ref() интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

CVSS3: 9
1%
Низкий
5 месяцев назад
redos логотип
ROS-20260831-80-0007

Уязвимость php 8.5

CVSS3: 9
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260831-80-0006

Уязвимость php 8.4

CVSS3: 9
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260831-80-0005

Уязвимость php 8.3

CVSS3: 9
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260831-80-0004

Уязвимость php

CVSS3: 9
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260831-73-0006

Уязвимость php 8.4

CVSS3: 9
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260831-73-0005

Уязвимость php 8.3

CVSS3: 9
1%
Низкий
около 1 месяца назад
redos логотип
ROS-20260831-73-0004

Уязвимость php

CVSS3: 9
1%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2091-1

Security update for php7

4 месяца назад
rocky логотип
RLSA-2026:34354

Important: php:7.4 security update

3 месяца назад
oracle-oval логотип
ELSA-2026-34354

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

3 месяца назад
rocky логотип
RLSA-2026:33449

Important: php security update

2 месяца назад
oracle-oval логотип
ELSA-2026-33449

ELSA-2026-33449: php security update (IMPORTANT)

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

5 месяцев назад

Уязвимостей на страницу