Количество 4 009
Количество 4 009
ELSA-2026-40416
ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW)
ELSA-2022-6158
ELSA-2022-6158: php:7.4 security update (MODERATE)
ELSA-2022-5904
ELSA-2022-5904: php security update (IMPORTANT)
ELSA-2022-5468
ELSA-2022-5468: php:8.0 security update (IMPORTANT)
ELSA-2022-5467
ELSA-2022-5467: php:7.4 security update (IMPORTANT)
ELSA-2018-0406
ELSA-2018-0406: php security update (MODERATE)
ELSA-2013-1813
ELSA-2013-1813: php53 and php security update (CRITICAL)
ELSA-2013-1050
ELSA-2013-1050: php53 security update (CRITICAL)
ELSA-2013-1049
ELSA-2013-1049: php security update (CRITICAL)
ELSA-2012-0093
ELSA-2012-0093: php security update (CRITICAL)
ELSA-2012-0092
ELSA-2012-0092: php53 security update (CRITICAL)
CVE-2026-7568
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.
CVE-2026-7568
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.
CVE-2026-7568
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.
CVE-2026-7568
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
CVE-2026-7263
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
CVE-2026-7263
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
CVE-2026-7263
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application.
CVE-2026-7263
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C ...
CVE-2026-7262
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2026-40416 ELSA-2026-40416: php:8.2 security, bug fix, and enhancement update (LOW) | 0% Низкий | 2 месяца назад | ||
ELSA-2022-6158 ELSA-2022-6158: php:7.4 security update (MODERATE) | 4% Низкий | около 4 лет назад | ||
ELSA-2022-5904 ELSA-2022-5904: php security update (IMPORTANT) | 58% Средний | около 4 лет назад | ||
ELSA-2022-5468 ELSA-2022-5468: php:8.0 security update (IMPORTANT) | 58% Средний | около 4 лет назад | ||
ELSA-2022-5467 ELSA-2022-5467: php:7.4 security update (IMPORTANT) | 58% Средний | около 4 лет назад | ||
ELSA-2018-0406 ELSA-2018-0406: php security update (MODERATE) | 3% Низкий | больше 8 лет назад | ||
ELSA-2013-1813 ELSA-2013-1813: php53 and php security update (CRITICAL) | 36% Средний | почти 13 лет назад | ||
ELSA-2013-1050 ELSA-2013-1050: php53 security update (CRITICAL) | 5% Низкий | около 13 лет назад | ||
ELSA-2013-1049 ELSA-2013-1049: php security update (CRITICAL) | 5% Низкий | около 13 лет назад | ||
ELSA-2012-0093 ELSA-2012-0093: php security update (CRITICAL) | 30% Средний | больше 14 лет назад | ||
ELSA-2012-0092 ELSA-2012-0092: php53 security update (CRITICAL) | 30% Средний | больше 14 лет назад | ||
CVE-2026-7568 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7568 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7568 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7568 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked list in the data structure representing the XML document. This may cause subsequent processing of the XML document to enter infinite loop, causing denial of service in the processing application. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7262 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу