Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 30

Количество 30

ubuntu логотип

CVE-2026-14355

2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2026-14355

2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-14355

2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
EPSS: Низкий
msrc логотип

CVE-2026-14355

2 месяца назад

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2026-14355

2 месяца назад

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...

CVSS3: 5.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3165-1

около 2 месяцев назад

Security update for php7

EPSS: Низкий
redos логотип

ROS-20260902-80-0029

13 дней назад

Уязвимость php 8.5

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260902-80-0028

13 дней назад

Уязвимость php 8.4

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260902-80-0027

13 дней назад

Уязвимость php 8.3

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260902-80-0026

13 дней назад

Уязвимость php

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260902-73-0027

13 дней назад

Уязвимость php 8.4

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260902-73-0026

13 дней назад

Уязвимость php 8.3

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260902-73-0025

13 дней назад

Уязвимость php

CVSS3: 5.3
EPSS: Низкий
rocky логотип

RLSA-2026:49914

около 1 месяца назад

Low: php8.4 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:48197

около 1 месяца назад

Low: php:8.3 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:48170

около 1 месяца назад

Low: php security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:47750

около 1 месяца назад

Low: php:7.4 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:47749

около 1 месяца назад

Low: php:8.2 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:40416

около 1 месяца назад

Low: php:8.2 security, bug fix, and enhancement update

EPSS: Низкий
github логотип

GHSA-7jrw-539f-x6vr

2 месяца назад

ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVSS3: 5.6
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-14355

ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD

CVSS3: 5.6
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before ...

CVSS3: 5.6
0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3165-1

Security update for php7

0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260902-80-0029

Уязвимость php 8.5

CVSS3: 5.3
0%
Низкий
13 дней назад
redos логотип
ROS-20260902-80-0028

Уязвимость php 8.4

CVSS3: 5.3
0%
Низкий
13 дней назад
redos логотип
ROS-20260902-80-0027

Уязвимость php 8.3

CVSS3: 5.3
0%
Низкий
13 дней назад
redos логотип
ROS-20260902-80-0026

Уязвимость php

CVSS3: 5.3
0%
Низкий
13 дней назад
redos логотип
ROS-20260902-73-0027

Уязвимость php 8.4

CVSS3: 5.3
0%
Низкий
13 дней назад
redos логотип
ROS-20260902-73-0026

Уязвимость php 8.3

CVSS3: 5.3
0%
Низкий
13 дней назад
redos логотип
ROS-20260902-73-0025

Уязвимость php

CVSS3: 5.3
0%
Низкий
13 дней назад
rocky логотип
RLSA-2026:49914

Low: php8.4 security, bug fix, and enhancement update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:48197

Low: php:8.3 security, bug fix, and enhancement update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:48170

Low: php security, bug fix, and enhancement update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:47750

Low: php:7.4 security, bug fix, and enhancement update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:47749

Low: php:8.2 security, bug fix, and enhancement update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:40416

Low: php:8.2 security, bug fix, and enhancement update

0%
Низкий
около 1 месяца назад
github логотип
GHSA-7jrw-539f-x6vr

ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD

CVSS3: 4.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу