CVE-2020-7061
- EPSS 2.06%
- Published 27.02.2020 21:15:18
- Last modified 21.11.2024 05:36:35
In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information ...
CVE-2014-3622
- EPSS 1.95%
- Published 19.02.2020 13:15:10
- Last modified 21.11.2024 02:08:31
Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.
CVE-2011-3336
- EPSS 24.64%
- Published 12.02.2020 20:15:13
- Last modified 21.11.2024 01:30:17
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
CVE-2020-7059
- EPSS 2.16%
- Published 10.02.2020 08:15:12
- Last modified 21.11.2024 05:36:35
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead t...
CVE-2020-7060
- EPSS 6.4%
- Published 10.02.2020 08:15:12
- Last modified 21.11.2024 05:36:35
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the alloc...
CVE-2015-2325
- EPSS 0.57%
- Published 14.01.2020 17:15:12
- Last modified 21.11.2024 02:27:13
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a gro...
CVE-2015-2326
- EPSS 0.3%
- Published 14.01.2020 17:15:12
- Last modified 21.11.2024 02:27:13
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call a...
CVE-2019-11045
- EPSS 35.84%
- Published 23.12.2019 03:15:11
- Last modified 21.11.2024 04:20:26
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications check...
CVE-2019-11046
- EPSS 7.89%
- Published 23.12.2019 03:15:11
- Last modified 21.11.2024 04:20:26
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are ide...
CVE-2019-11047
- EPSS 3.17%
- Published 23.12.2019 03:15:11
- Last modified 21.11.2024 04:20:26
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocate...