php

756 tracked vulnerabilities.

CVE-2017-11142 HIGH
PHP < 5.6.31, 7.x < 7.0.17, 7.1.x < 7.1.3 - Denial of Service via Long Form Variables
Jul 10, 2017
CVSS 7.5
EPSS 0.15
CVE-2017-9229 HIGH
Oniguruma 6.2.0 - Memory Corruption
May 24, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-9228 CRITICAL
Oniguruma 6.2.0 - Memory Corruption
May 24, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-9227 CRITICAL
Oniguruma 6.2.0 - Memory Corruption
May 24, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-9226 CRITICAL
Oniguruma <6.2.0 - Memory Corruption
May 24, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-9225 CRITICAL
Oniguruma <6.2.0 - Memory Corruption
May 24, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-9224 CRITICAL
Oniguruma <6.2.0 - Memory Corruption
May 24, 2017
CVSS 9.8
EPSS 0.01
CVE-2017-9119 CRITICAL
PHP 7.1.5 - Denial of Service via Crafted Array Operations
May 21, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-9067 HIGH
MODX Revolution <2.5.7 - Path Traversal
May 18, 2017
CVSS 7.0
EPSS 0.00
CVE-2017-8923 CRITICAL
PHP < 7.4.24 - Out-of-bounds Write via zend_string_extend
May 12, 2017
CVSS 9.8
EPSS 0.05
CVE-2017-7963 HIGH
PHP < 7.1.4 - Denial of Service via GMP Long String Operations
Apr 19, 2017
CVSS 7.5
EPSS 0.02
CVE-2017-6441 HIGH
PHP 7.1.2 - Denial of Service via NULL Pointer Dereference in _zval_get_long_func_ex
Apr 03, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-7272 HIGH
PHP < 7.1.3 - Server-Side Request Forgery via fsockopen/pfsockopen Port Parsing
Mar 27, 2017
CVSS 7.4
EPSS 0.01
CVE-2017-5630 HIGH
PEAR Base System 1.10.1 - Arbitrary File Overwrite via Unvalidated Redirect Response
Feb 01, 2017
CVSS 7.5
EPSS 0.05
CVE-2017-5340 CRITICAL
PHP 7.0.0-7.0.14 - Remote Code Execution via Crafted Serialized Data
Jan 11, 2017
CVSS 9.8
EPSS 0.07
CVE-2016-7398 CRITICAL
PHP <3.1.0beta2, <2.6.0beta2 - Code Injection
Sep 06, 2019
CVSS 9.8
EPSS 0.06
CVE-2016-10712 HIGH
PHP < 5.5.32, 5.6.x < 5.6.18, 7.x < 7.0.3 - Input Validation Bypass via Stream Metadata Manipulation
Feb 09, 2018
CVSS 7.5
EPSS 0.01
CVE-2016-10397 HIGH
PHP < 5.6.28 and 7.x < 7.0.13 - URL Parsing Bypass via Incorrect Hostname Validation
Jul 10, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-4473 CRITICAL
PHP 5.6.x and 7.0.7 - Remote Code Execution via Use-After-Free in phar_object.c
Jun 08, 2017
CVSS 9.8
EPSS 0.17
CVE-2016-5399 HIGH
PHP < 5.5.37 - Out-of-bounds Write via bzread Function
Apr 21, 2017
CVSS 7.8
EPSS 0.14
CVE-2016-10162 HIGH
PHP 7.0.x < 7.0.15 and 7.1.x < 7.1.1 - Denial of Service via WDDX Deserialization NULL Pointer Dereference
Jan 24, 2017
CVSS 7.5
EPSS 0.05
CVE-2016-10161 HIGH
PHP < 5.6.30, 7.0.x < 7.0.15, 7.1.x < 7.1.1 - Denial of Service via Crafted Serialized Data
Jan 24, 2017
CVSS 7.5
EPSS 0.18
CVE-2016-10160 CRITICAL
PHP <5.6.30, <7.0.15 - Memory Corruption
Jan 24, 2017
CVSS 9.8
EPSS 0.05
CVE-2016-10159 HIGH
PHP < 5.6.30 and 7.0.x < 7.0.15 - Denial of Service via Truncated PHAR Archive Manifest
Jan 24, 2017
CVSS 7.5
EPSS 0.08
CVE-2016-10158 HIGH
PHP < 5.6.30, 7.0.x < 7.0.15, 7.1.x < 7.1.1 - Denial of Service via EXIF Data Integer Division
Jan 24, 2017
CVSS 7.5
EPSS 0.05