CVE-2024-8927
- EPSS 0.33%
- Veröffentlicht 08.10.2024 04:15:10
- Zuletzt bearbeitet 03.11.2025 23:17:33
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can b...
CVE-2024-8925
- EPSS 1.78%
- Veröffentlicht 08.10.2024 04:15:09
- Zuletzt bearbeitet 03.11.2025 23:17:32
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to...
CVE-2024-2408
- EPSS 0.26%
- Veröffentlicht 09.06.2024 20:15:09
- Zuletzt bearbeitet 21.03.2025 18:15:32
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https...
CVE-2024-4577
- EPSS 94.37%
- Veröffentlicht 09.06.2024 20:15:09
- Zuletzt bearbeitet 03.11.2025 19:23:39
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given...
CVE-2024-5458
- EPSS 4.31%
- Veröffentlicht 09.06.2024 19:15:52
- Zuletzt bearbeitet 03.11.2025 23:17:30
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid u...
CVE-2024-5585
- EPSS 0.9%
- Veröffentlicht 09.06.2024 19:15:52
- Zuletzt bearbeitet 21.11.2024 09:47:58
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient ...
CVE-2024-2757
- EPSS 0.63%
- Veröffentlicht 29.04.2024 04:15:08
- Zuletzt bearbeitet 04.11.2025 18:16:18
In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application ...
CVE-2024-3096
- EPSS 1.07%
- Veröffentlicht 29.04.2024 04:15:08
- Zuletzt bearbeitet 04.11.2025 18:16:30
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
CVE-2024-1874
- EPSS 57.55%
- Veröffentlicht 29.04.2024 04:15:07
- Zuletzt bearbeitet 04.11.2025 19:16:27
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can su...
CVE-2024-2756
- EPSS 9.76%
- Veröffentlicht 29.04.2024 04:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:18
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applic...