CVE-2025-1219
- EPSS 0.07%
- Veröffentlicht 30.03.2025 06:15:13
- Zuletzt bearbeitet 03.11.2025 21:18:52
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when t...
CVE-2025-1217
- EPSS 0.1%
- Veröffentlicht 29.03.2025 05:19:33
- Zuletzt bearbeitet 03.11.2025 21:18:52
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreti...
CVE-2022-31631
- EPSS 0.78%
- Veröffentlicht 12.02.2025 22:15:29
- Zuletzt bearbeitet 02.07.2025 21:35:56
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may furthe...
CVE-2024-11233
- EPSS 0.16%
- Veröffentlicht 24.11.2024 02:15:16
- Zuletzt bearbeitet 03.11.2025 22:16:37
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or discl...
CVE-2024-11236
- EPSS 0.33%
- Veröffentlicht 24.11.2024 01:15:04
- Zuletzt bearbeitet 03.11.2025 22:16:37
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
CVE-2024-11234
- EPSS 0.46%
- Veröffentlicht 24.11.2024 01:15:03
- Zuletzt bearbeitet 03.11.2025 22:16:37
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to...
CVE-2024-8929
- EPSS 0.14%
- Veröffentlicht 22.11.2024 07:15:03
- Zuletzt bearbeitet 03.11.2025 23:17:33
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different user...
CVE-2024-8932
- EPSS 0.28%
- Veröffentlicht 22.11.2024 06:15:20
- Zuletzt bearbeitet 03.11.2025 23:17:33
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
CVE-2024-9026
- EPSS 0.66%
- Veröffentlicht 08.10.2024 04:15:11
- Zuletzt bearbeitet 03.11.2025 23:17:33
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 char...
CVE-2024-8926
- EPSS 2.24%
- Veröffentlicht 08.10.2024 04:15:10
- Zuletzt bearbeitet 03.11.2025 23:17:32
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3 may still be bypasse...