Логотип exploitDog
bind:"CVE-2025-14177" OR bind:"CVE-2025-14178" OR bind:"CVE-2025-14180"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-14177" OR bind:"CVE-2025-14178" OR bind:"CVE-2025-14180"

Количество 37

Количество 37

suse-cvrf логотип

openSUSE-SU-2026:20113-1

около 2 месяцев назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0086-1

3 месяца назад

Security update for php8

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0071-1

3 месяца назад

Security update for php8

EPSS: Низкий
rocky логотип

RLSA-2026:1628

около 2 месяцев назад

Important: php security update

EPSS: Низкий
rocky логотип

RLSA-2026:1429

около 2 месяцев назад

Important: php:8.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1628

около 2 месяцев назад

ELSA-2026-1628: php security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1429

около 2 месяцев назад

ELSA-2026-1429: php:8.3 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:1412

около 2 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:1409

около 2 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1412

около 2 месяцев назад

ELSA-2026-1412: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-1409

около 2 месяцев назад

ELSA-2026-1409: php:8.2 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:2799

29 дней назад

Moderate: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2799

около 1 месяца назад

ELSA-2026-2799: php security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2025-14177

3 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-14177

3 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-14177

3 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-14177

3 месяца назад

Information Leak of Memory in getimagesize

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2025-14177

3 месяца назад

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:2470

около 1 месяца назад

Moderate: php:7.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-2470

около 1 месяца назад

ELSA-2026-2470: php:7.4 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
openSUSE-SU-2026:20113-1

Security update for php8

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0086-1

Security update for php8

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0071-1

Security update for php8

3 месяца назад
rocky логотип
RLSA-2026:1628

Important: php security update

около 2 месяцев назад
rocky логотип
RLSA-2026:1429

Important: php:8.3 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-1628

ELSA-2026-1628: php security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-1429

ELSA-2026-1429: php:8.3 security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:1412

Important: php:8.2 security update

около 2 месяцев назад
rocky логотип
RLSA-2026:1409

Important: php:8.2 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-1412

ELSA-2026-1412: php:8.2 security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-1409

ELSA-2026-1409: php:8.2 security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:2799

Moderate: php security update

29 дней назад
oracle-oval логотип
ELSA-2026-2799

ELSA-2026-2799: php security update (MODERATE)

около 1 месяца назад
ubuntu логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 3.7
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2025-14177

Information Leak of Memory in getimagesize

CVSS3: 3.7
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:2470

Moderate: php:7.4 security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-2470

ELSA-2026-2470: php:7.4 security update (MODERATE)

около 1 месяца назад

Уязвимостей на страницу