Количество 3 883
Количество 3 883
SUSE-SU-2018:3986-1
Recommended update for php53
SUSE-SU-2018:3018-1
Security update for php53
SUSE-SU-2018:3017-1
Security update for php5
SUSE-SU-2018:3016-1
Security update for php7
SUSE-SU-2018:2887-1
Security update for php7
SUSE-SU-2018:2640-1
Security update for php7
SUSE-SU-2018:1936-2
Security update for php7
SUSE-SU-2018:1936-1
Security update for php7
SUSE-SU-2018:1886-1
Security update for php7
SUSE-SU-2016:3251-1
Security update for gd
SUSE-SU-2016:3211-1
Security update for gd
SUSE-SU-2015:0866-1
Security update for gd
SUSE-SU-2015:0835-1
Security update for gd
SUSE-SU-2015:0668-1
Security update for libzip
GHSA-xr89-hqhp-26m9
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
GHSA-x66w-7mq7-3gxp
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
GHSA-x3xg-pxf8-v7j9
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.
GHSA-wvv6-mrff-rp8j
An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.
GHSA-wvm5-62cm-hw4m
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
GHSA-wpvc-3mh7-8pwj
PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2018:3986-1 Recommended update for php53 | 94% Критический | около 7 лет назад | ||
SUSE-SU-2018:3018-1 Security update for php53 | 8% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:3017-1 Security update for php5 | 8% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:3016-1 Security update for php7 | 8% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:2887-1 Security update for php7 | 8% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:2640-1 Security update for php7 | 0% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:1936-2 Security update for php7 | 6% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:1936-1 Security update for php7 | 6% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:1886-1 Security update for php7 | 6% Низкий | больше 7 лет назад | ||
SUSE-SU-2016:3251-1 Security update for gd | 11% Средний | около 9 лет назад | ||
SUSE-SU-2016:3211-1 Security update for gd | 11% Средний | около 9 лет назад | ||
SUSE-SU-2015:0866-1 Security update for gd | 17% Средний | почти 11 лет назад | ||
SUSE-SU-2015:0835-1 Security update for gd | 17% Средний | почти 11 лет назад | ||
SUSE-SU-2015:0668-1 Security update for libzip | 43% Средний | почти 11 лет назад | ||
GHSA-xr89-hqhp-26m9 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash. | CVSS3: 9.1 | 2% Низкий | больше 3 лет назад | |
GHSA-x66w-7mq7-3gxp PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
GHSA-x3xg-pxf8-v7j9 The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index. | CVSS3: 7.5 | 16% Средний | больше 3 лет назад | |
GHSA-wvv6-mrff-rp8j An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries. | CVSS3: 7.5 | 8% Низкий | больше 3 лет назад | |
GHSA-wvm5-62cm-hw4m An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF. | CVSS3: 9.8 | 52% Средний | больше 3 лет назад | |
GHSA-wpvc-3mh7-8pwj PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror. | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад |
Уязвимостей на страницу