Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-6104

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-6104

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-6104

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-6104

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ...

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260831-80-0028

15 дней назад

Уязвимость php 8.5

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260831-80-0027

15 дней назад

Уязвимость php 8.4

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260831-80-0026

15 дней назад

Уязвимость php 8.3

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260831-80-0025

15 дней назад

Уязвимость php

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260831-73-0022

15 дней назад

Уязвимость php 8.4

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260831-73-0021

15 дней назад

Уязвимость php 8.3

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260831-73-0020

15 дней назад

Уязвимость php

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-74r9-qxhc-fx53

4 месяца назад

Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding

EPSS: Низкий
fstec логотип

BDU:2026-13295

4 месяца назад

Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения

CVSS3: 8.2
EPSS: Низкий
rocky логотип

RLSA-2026:22649

3 месяца назад

Important: php8.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22649

2 месяца назад

ELSA-2026-22649: php8.4 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20745-1

4 месяца назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 9.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 8.2
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.

CVSS3: 9.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ...

CVSS3: 9.1
0%
Низкий
4 месяца назад
redos логотип
ROS-20260831-80-0028

Уязвимость php 8.5

CVSS3: 7.2
0%
Низкий
15 дней назад
redos логотип
ROS-20260831-80-0027

Уязвимость php 8.4

CVSS3: 7.2
0%
Низкий
15 дней назад
redos логотип
ROS-20260831-80-0026

Уязвимость php 8.3

CVSS3: 7.2
0%
Низкий
15 дней назад
redos логотип
ROS-20260831-80-0025

Уязвимость php

CVSS3: 7.2
0%
Низкий
15 дней назад
redos логотип
ROS-20260831-73-0022

Уязвимость php 8.4

CVSS3: 7.2
0%
Низкий
15 дней назад
redos логотип
ROS-20260831-73-0021

Уязвимость php 8.3

CVSS3: 7.2
0%
Низкий
15 дней назад
redos логотип
ROS-20260831-73-0020

Уязвимость php

CVSS3: 7.2
0%
Низкий
15 дней назад
github логотип
GHSA-74r9-qxhc-fx53

Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding

0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-13295

Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения

CVSS3: 8.2
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:22649

Important: php8.4 security update

3 месяца назад
oracle-oval логотип
ELSA-2026-22649

ELSA-2026-22649: php8.4 security update (IMPORTANT)

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20745-1

Security update for php8

4 месяца назад

Уязвимостей на страницу