Количество 3 954
Количество 3 954
SUSE-SU-2021:0584-1
Security update for php7
SUSE-SU-2021:0522-1
Security update for php74
SUSE-SU-2021:0498-1
Security update for php72
SUSE-SU-2021:0494-1
Security update for php7
SUSE-SU-2020:2920-1
Security update for php7
SUSE-SU-2020:2894-1
Security update for php5
SUSE-SU-2020:14516-1
Security update for php53
SUSE-SU-2019:2909-1
Security update for php72
SUSE-SU-2019:2819-1
Security update for php7
SUSE-SU-2019:2809-1
Security update for php7
SUSE-SU-2019:0449-1
Security update for php5
RLSA-2019:3736
Critical: php:7.3 security update
RLSA-2019:3735
Critical: php:7.2 security update
GHSA-xcj5-5h7j-93q8
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.
GHSA-x3rx-2m8v-q2vm
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.2.8, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
GHSA-rxcr-7xjm-f9c9
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.
GHSA-r9gg-92mp-v9h5
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.
GHSA-qh78-qfw9-93x9
In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.
GHSA-q8qf-vj8v-x7r9
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
GHSA-pg67-q5vx-48xq
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2021:0584-1 Security update for php7 | 3% Низкий | больше 5 лет назад | ||
SUSE-SU-2021:0522-1 Security update for php74 | 3% Низкий | больше 5 лет назад | ||
SUSE-SU-2021:0498-1 Security update for php72 | 3% Низкий | больше 5 лет назад | ||
SUSE-SU-2021:0494-1 Security update for php7 | 3% Низкий | больше 5 лет назад | ||
SUSE-SU-2020:2920-1 Security update for php7 | 5% Низкий | почти 6 лет назад | ||
SUSE-SU-2020:2894-1 Security update for php5 | 5% Низкий | почти 6 лет назад | ||
SUSE-SU-2020:14516-1 Security update for php53 | 5% Низкий | почти 6 лет назад | ||
SUSE-SU-2019:2909-1 Security update for php72 | 99% Критический | больше 6 лет назад | ||
SUSE-SU-2019:2819-1 Security update for php7 | 99% Критический | почти 7 лет назад | ||
SUSE-SU-2019:2809-1 Security update for php7 | 99% Критический | почти 7 лет назад | ||
SUSE-SU-2019:0449-1 Security update for php5 | 64% Средний | больше 7 лет назад | ||
RLSA-2019:3736 Critical: php:7.3 security update | 99% Критический | больше 6 лет назад | ||
RLSA-2019:3735 Critical: php:7.2 security update | 99% Критический | больше 6 лет назад | ||
GHSA-xcj5-5h7j-93q8 An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn. | CVSS3: 7.5 | 6% Низкий | около 4 лет назад | |
GHSA-x3rx-2m8v-q2vm When processing certain files, PHP EXIF extension in versions 7.1.x below 7.2.8, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash. | CVSS3: 9.1 | 4% Низкий | около 4 лет назад | |
GHSA-rxcr-7xjm-f9c9 In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-r9gg-92mp-v9h5 The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures. | CVSS3: 9.8 | 4% Низкий | около 4 лет назад | |
GHSA-qh78-qfw9-93x9 In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended. | CVSS3: 5.3 | 26% Средний | больше 4 лет назад | |
GHSA-q8qf-vj8v-x7r9 When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash. | CVSS3: 9.1 | 7% Низкий | около 4 лет назад | |
GHSA-pg67-q5vx-48xq When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash. | CVSS3: 7.1 | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу