Количество 20
Количество 20
GHSA-74r9-qxhc-fx53
Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings.
CVE-2026-6104
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ...
ROS-20260831-80-0028
Уязвимость php 8.5
ROS-20260831-80-0027
Уязвимость php 8.4
ROS-20260831-80-0026
Уязвимость php 8.3
ROS-20260831-80-0025
Уязвимость php
ROS-20260831-73-0022
Уязвимость php 8.4
ROS-20260831-73-0021
Уязвимость php 8.3
ROS-20260831-73-0020
Уязвимость php
BDU:2026-13295
Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения
RLSA-2026:22649
Important: php8.4 security update
ELSA-2026-22649
ELSA-2026-22649: php8.4 security update (IMPORTANT)
openSUSE-SU-2026:20745-1
Security update for php8
ALT-PU-2026-8354
ALT-PU-2026-8354: package `php8.4-soap` update to version 8.4.21-alt1
ALT-PU-2026-8278
ALT-PU-2026-8278: package `php8.5-soap` update to version 8.5.6-alt1
ALT-PU-2026-8037
ALT-PU-2026-8037: package `php8.4` update to version 8.4.21-alt1
ALT-PU-2026-8005
ALT-PU-2026-8005: package `php8.5` update to version 8.5.6-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-74r9-qxhc-fx53 Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding | 1% Низкий | 5 месяцев назад | ||
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings. | CVSS3: 9.1 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings. | CVSS3: 8.2 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or crash. Affected functions include mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables(), and mb_detect_order(), as well as the mbstring.detect_order and mbstring.http_output INI settings. | CVSS3: 9.1 | 1% Низкий | 5 месяцев назад | |
CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an en ... | CVSS3: 9.1 | 1% Низкий | 5 месяцев назад | |
ROS-20260831-80-0028 Уязвимость php 8.5 | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-80-0027 Уязвимость php 8.4 | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-80-0026 Уязвимость php 8.3 | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-80-0025 Уязвимость php | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-73-0022 Уязвимость php 8.4 | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-73-0021 Уязвимость php 8.3 | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
ROS-20260831-73-0020 Уязвимость php | CVSS3: 7.2 | 1% Низкий | около 1 месяца назад | |
BDU:2026-13295 Уязвимость функций mb_convert_encoding(), mb_detect_encoding(), mb_convert_variables() и mb_detect_order() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать аварийное завершение работы приложения | CVSS3: 8.2 | 1% Низкий | 5 месяцев назад | |
RLSA-2026:22649 Important: php8.4 security update | 4 месяца назад | |||
ELSA-2026-22649 ELSA-2026-22649: php8.4 security update (IMPORTANT) | 3 месяца назад | |||
openSUSE-SU-2026:20745-1 Security update for php8 | 5 месяцев назад | |||
ALT-PU-2026-8354 ALT-PU-2026-8354: package `php8.4-soap` update to version 8.4.21-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8278 ALT-PU-2026-8278: package `php8.5-soap` update to version 8.5.6-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8037 ALT-PU-2026-8037: package `php8.4` update to version 8.4.21-alt1 | CVSS3: 9.8 | 4 месяца назад | ||
ALT-PU-2026-8005 ALT-PU-2026-8005: package `php8.5` update to version 8.5.6-alt1 | CVSS3: 9.8 | 4 месяца назад |
Уязвимостей на страницу