Search CVE reports
121 – 130 of 659 results
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application...
4 affected packages
php5, php7.0, php7.1, php7.2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | — | — | Not in release |
| php7.0 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |
| php7.2 | — | — | — | Fixed |
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for...
4 affected packages
php5, php7.0, php7.1, php7.2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | — | — | Not in release |
| php7.0 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |
| php7.2 | — | — | — | Fixed |
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
4 affected packages
php5, php7.0, php7.1, php7.2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | — | — | Not in release |
| php7.0 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |
| php7.2 | — | — | — | Fixed |
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl...
4 affected packages
php7.0, php7.1, php5, php7.2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php7.0 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |
| php5 | — | — | — | Not in release |
| php7.2 | — | — | — | Fixed |
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function...
4 affected packages
php5, php7.0, php7.1, php7.2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | — | — | Not in release |
| php7.0 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |
| php7.2 | — | — | — | Fixed |
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec,...
4 affected packages
php5, php7.0, php7.2, php7.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | Not in release | Not in release | Not in release |
| php7.0 | — | Not in release | Not in release | Not in release |
| php7.2 | — | Not in release | Not in release | Fixed |
| php7.3 | — | Not in release | Not in release | Not in release |
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri...
3 affected packages
php7.0, php5, php7.1
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php7.0 | — | — | — | Not in release |
| php5 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.
4 affected packages
php7.1, php5, php7.0, php7.2
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php7.1 | — | — | — | Not in release |
| php5 | — | — | — | Not in release |
| php7.0 | — | — | — | Not in release |
| php7.2 | — | — | — | Not affected |
Some fixes available 9 of 10
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF...
4 affected packages
php5, libgd2, php7.0, php7.1
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | — | Not in release | Not in release |
| libgd2 | — | — | Fixed | Fixed |
| php7.0 | — | — | Not in release | Not in release |
| php7.1 | — | — | Not in release | Not in release |
Some fixes available 2 of 3
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak...
3 affected packages
php5, php7.0, php7.1
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | — | — | — | Not in release |
| php7.0 | — | — | — | Not in release |
| php7.1 | — | — | — | Not in release |