Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-91767

10 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-91767

10 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-91767

10 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-91767

8 дней назад

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-91767

10 дней назад

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xr7j-rvgx-xq5p

11 дней назад

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-91767

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
0%
Низкий
10 дней назад
redhat логотип
CVE-2026-91767

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
0%
Низкий
10 дней назад
nvd логотип
CVE-2026-91767

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes the PHP client read up to SIZE_MAX bytes past the end of a heap allocation. The path is reachable from any default client stream, because verify_peer_name is enabled by default.

CVSS3: 6.5
0%
Низкий
10 дней назад
msrc логотип
CVE-2026-91767

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

CVSS3: 6.5
0%
Низкий
8 дней назад
debian логотип
CVE-2026-91767

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows ...

CVSS3: 6.5
0%
Низкий
10 дней назад
github логотип
GHSA-xr7j-rvgx-xq5p

Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN

CVSS3: 6.5
0%
Низкий
11 дней назад

Уязвимостей на страницу