Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 009

Количество 4 009

oracle-oval логотип

ELSA-2026-40416

2 месяца назад

ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-6158

около 4 лет назад

ELSA-2022-6158: php:7.4 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-5904

около 4 лет назад

ELSA-2022-5904: php security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2022-5468

около 4 лет назад

ELSA-2022-5468: php:8.0 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2022-5467

около 4 лет назад

ELSA-2022-5467: php:7.4 security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2018-0406

больше 8 лет назад

ELSA-2018-0406: php security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-1813

почти 13 лет назад

ELSA-2013-1813: php53 and php security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2013-1050

около 13 лет назад

ELSA-2013-1050: php53 security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2013-1049

около 13 лет назад

ELSA-2013-1049: php security update (CRITICAL)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-0093

больше 14 лет назад

ELSA-2012-0093: php security update (CRITICAL)

EPSS: Средний
oracle-oval логотип

ELSA-2012-0092

больше 14 лет назад

ELSA-2012-0092: php53 security update (CRITICAL)

EPSS: Средний
ubuntu логотип

CVE-2026-7568

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-7568

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-7568

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-7568

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-7263

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-7263

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-7263

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-7263

4 месяца назад

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-7262

4 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-40416

ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)

0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2022-6158

ELSA-2022-6158: php:7.4 security update (MODERATE)

4%
Низкий
около 4 лет назад
oracle-oval логотип
ELSA-2022-5904

ELSA-2022-5904: php security update (IMPORTANT)

58%
Средний
около 4 лет назад
oracle-oval логотип
ELSA-2022-5468

ELSA-2022-5468: php:8.0 security update (IMPORTANT)

58%
Средний
около 4 лет назад
oracle-oval логотип
ELSA-2022-5467

ELSA-2022-5467: php:7.4 security update (IMPORTANT)

58%
Средний
около 4 лет назад
oracle-oval логотип
ELSA-2018-0406

ELSA-2018-0406: php security update (MODERATE)

3%
Низкий
больше 8 лет назад
oracle-oval логотип
ELSA-2013-1813

ELSA-2013-1813: php53 and php security update (CRITICAL)

36%
Средний
почти 13 лет назад
oracle-oval логотип
ELSA-2013-1050

ELSA-2013-1050: php53 security update (CRITICAL)

5%
Низкий
около 13 лет назад
oracle-oval логотип
ELSA-2013-1049

ELSA-2013-1049: php security update (CRITICAL)

5%
Низкий
около 13 лет назад
oracle-oval логотип
ELSA-2012-0093

ELSA-2012-0093: php security update (CRITICAL)

30%
Средний
больше 14 лет назад
oracle-oval логотип
ELSA-2012-0092

ELSA-2012-0092: php53 security update (CRITICAL)

30%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-7262

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element.  This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.

CVSS3: 7.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу