Количество 16
Количество 16
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ...
ROS-20260831-80-0028
Уязвимость php 8.5
ROS-20260831-80-0027
Уязвимость php 8.4
ROS-20260831-80-0026
Уязвимость php 8.3
ROS-20260831-80-0025
Уязвимость php
ROS-20260831-73-0022
Уязвимость php 8.4
ROS-20260831-73-0021
Уязвимость php 8.3
ROS-20260831-73-0020
Уязвимость php
GHSA-74r9-qxhc-fx53
Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding
BDU:2026-13295
Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения
RLSA-2026:22649
Important: php8.4 security update
ELSA-2026-22649
ELSA-2026-22649: php8.4 security update (IMPORTANT)
openSUSE-SU-2026:20745-1
Security update for php8
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings. | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ... | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
ROS-20260831-80-0028 Уязвимость php 8.5 | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
ROS-20260831-80-0027 Уязвимость php 8.4 | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
ROS-20260831-80-0026 Уязвимость php 8.3 | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
ROS-20260831-80-0025 Уязвимость php | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
ROS-20260831-73-0022 Уязвимость php 8.4 | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
ROS-20260831-73-0021 Уязвимость php 8.3 | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
ROS-20260831-73-0020 Уязвимость php | CVSS3: 7.2 | 0% Низкий | 15 дней назад | |
GHSA-74r9-qxhc-fx53 Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding | 0% Низкий | 4 месяца назад | ||
BDU:2026-13295 Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
RLSA-2026:22649 Important: php8.4 security update | 3 месяца назад | |||
ELSA-2026-22649 ELSA-2026-22649: php8.4 security update (IMPORTANT) | 2 месяца назад | |||
openSUSE-SU-2026:20745-1 Security update for php8 | 4 месяца назад |
Уязвимостей на страницу