Количество 33
Количество 33
BDU:2026-08591
Уязвимость функции urldecode() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260901-80-0008
Уязвимость php 8.5
ROS-20260901-80-0007
Уязвимость php 8.4
ROS-20260901-80-0006
Уязвимость php 8.3
ROS-20260901-80-0005
Уязвимость php
ROS-20260901-73-0006
Уязвимость php 8.4
ROS-20260901-73-0005
Уязвимость php 8.3
ROS-20260901-73-0004
Уязвимость php
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
Out-of-bounds read in urldecode() on NetBSD
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-m8rr-4c36-8gq4
Out-of-bounds read in urldecode()
RLSA-2026:22305
Important: php:8.2 security update
RLSA-2026:22143
Important: php:8.2 security update
RLSA-2026:22142
Important: php:8.3 security update
ELSA-2026-22305
ELSA-2026-22305: php:8.2 security update (IMPORTANT)
ELSA-2026-22143
ELSA-2026-22143: php:8.2 security update (IMPORTANT)
ELSA-2026-22142
ELSA-2026-22142: php:8.3 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-08591 Уязвимость функции urldecode() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
ROS-20260901-80-0008 Уязвимость php 8.5 | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0007 Уязвимость php 8.4 | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0006 Уязвимость php 8.3 | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0005 Уязвимость php | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0006 Уязвимость php 8.4 | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0005 Уязвимость php 8.3 | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0004 Уязвимость php | CVSS3: 7.5 | 0% Низкий | 14 дней назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7258 Out-of-bounds read in urldecode() on NetBSD | 0% Низкий | 4 месяца назад | ||
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-m8rr-4c36-8gq4 Out-of-bounds read in urldecode() | 0% Низкий | 4 месяца назад | ||
RLSA-2026:22305 Important: php:8.2 security update | 4 месяца назад | |||
RLSA-2026:22143 Important: php:8.2 security update | 4 месяца назад | |||
RLSA-2026:22142 Important: php:8.3 security update | 4 месяца назад | |||
ELSA-2026-22305 ELSA-2026-22305: php:8.2 security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-22143 ELSA-2026-22143: php:8.2 security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-22142 ELSA-2026-22142: php:8.3 security update (IMPORTANT) | 3 месяца назад |
Уязвимостей на страницу