Количество 3 768
Количество 3 768

SUSE-SU-2018:2887-1
Security update for php7

SUSE-SU-2018:2640-1
Security update for php7

SUSE-SU-2018:1936-2
Security update for php7

SUSE-SU-2018:1936-1
Security update for php7

SUSE-SU-2018:1886-1
Security update for php7

SUSE-SU-2016:3251-1
Security update for gd

SUSE-SU-2016:3211-1
Security update for gd

SUSE-SU-2015:0866-1
Security update for gd

SUSE-SU-2015:0835-1
Security update for gd

SUSE-SU-2015:0668-1
Security update for libzip
GHSA-xr89-hqhp-26m9
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
GHSA-x66w-7mq7-3gxp
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
GHSA-x3xg-pxf8-v7j9
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.
GHSA-wvv6-mrff-rp8j
An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.
GHSA-wvm5-62cm-hw4m
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
GHSA-wpvc-3mh7-8pwj
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
GHSA-wpfq-fvm4-44jm
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.
GHSA-wfcw-88hm-m2xm
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.
GHSA-w8f6-vcfx-23xp
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.
GHSA-w7xp-2c87-fchc
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | SUSE-SU-2018:2887-1 Security update for php7 | 26% Средний | почти 7 лет назад | |
![]() | SUSE-SU-2018:2640-1 Security update for php7 | 0% Низкий | почти 7 лет назад | |
![]() | SUSE-SU-2018:1936-2 Security update for php7 | 4% Низкий | почти 7 лет назад | |
![]() | SUSE-SU-2018:1936-1 Security update for php7 | 4% Низкий | почти 7 лет назад | |
![]() | SUSE-SU-2018:1886-1 Security update for php7 | 4% Низкий | почти 7 лет назад | |
![]() | SUSE-SU-2016:3251-1 Security update for gd | 11% Средний | больше 8 лет назад | |
![]() | SUSE-SU-2016:3211-1 Security update for gd | 11% Средний | больше 8 лет назад | |
![]() | SUSE-SU-2015:0866-1 Security update for gd | 15% Средний | больше 10 лет назад | |
![]() | SUSE-SU-2015:0835-1 Security update for gd | 15% Средний | больше 10 лет назад | |
![]() | SUSE-SU-2015:0668-1 Security update for libzip | 43% Средний | больше 10 лет назад | |
GHSA-xr89-hqhp-26m9 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash. | CVSS3: 9.1 | 1% Низкий | около 3 лет назад | |
GHSA-x66w-7mq7-3gxp PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | CVSS3: 9.8 | 7% Низкий | около 3 лет назад | |
GHSA-x3xg-pxf8-v7j9 The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index. | CVSS3: 7.5 | 11% Средний | около 3 лет назад | |
GHSA-wvv6-mrff-rp8j An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries. | CVSS3: 7.5 | 7% Низкий | около 3 лет назад | |
GHSA-wvm5-62cm-hw4m An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF. | CVSS3: 9.8 | 51% Средний | около 3 лет назад | |
GHSA-wpvc-3mh7-8pwj PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | CVSS3: 9.8 | 3% Низкий | около 3 лет назад | |
GHSA-wpfq-fvm4-44jm applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter. | CVSS3: 8.1 | 20% Средний | около 3 лет назад | |
GHSA-wfcw-88hm-m2xm Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow. | 43% Средний | около 3 лет назад | ||
GHSA-w8f6-vcfx-23xp In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c. | CVSS3: 9.1 | 2% Низкий | около 3 лет назад | |
GHSA-w7xp-2c87-fchc The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information. | 3% Низкий | около 3 лет назад |
Уязвимостей на страницу