Search CVE reports
1 – 10 of 122 results
Some fixes available 3 of 8
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | — | — |
php7.0 | Not in release | Not in release | — | — |
php7.2 | Not in release | Not in release | — | Needs evaluation |
php7.4 | Not in release | Not in release | Needs evaluation | — |
php8.1 | Not in release | Fixed | — | — |
php8.3 | Fixed | Not in release | — | — |
php8.4 | Not in release | Not in release | — | — |
Some fixes available 7 of 8
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size...
7 affected packages
php7.2, php5, php7.0, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php7.2 | Not in release | Not in release | Not in release | Fixed |
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
php8.4 | Not in release | Not in release | Not in release | — |
Some fixes available 6 of 8
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Fixed |
php7.4 | Not in release | Not in release | Vulnerable | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
php8.4 | Not in release | Not in release | Not in release | — |
Some fixes available 3 of 8
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | — | — |
php7.0 | Not in release | Not in release | — | — |
php7.2 | Not in release | Not in release | — | Needs evaluation |
php7.4 | Not in release | Not in release | Needs evaluation | — |
php8.1 | Not in release | Fixed | — | — |
php8.3 | Fixed | Not in release | — | — |
php8.4 | Not in release | Not in release | — | — |
Some fixes available 7 of 8
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Fixed |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
php8.4 | Not in release | Not in release | Not in release | — |
Some fixes available 3 of 8
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other...
7 affected packages
php8.4, php5, php7.0, php7.2, php7.4...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php8.4 | Not in release | Not in release | — | — |
php5 | Not in release | Not in release | — | — |
php7.0 | Not in release | Not in release | — | — |
php7.2 | Not in release | Not in release | — | Needs evaluation |
php7.4 | Not in release | Not in release | Needs evaluation | — |
php8.1 | Not in release | Fixed | — | — |
php8.3 | Fixed | Not in release | — | — |
Some fixes available 4 of 5
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Not affected |
php7.4 | Not in release | Not in release | Vulnerable | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
php8.4 | Not in release | Not in release | Not in release | — |
Some fixes available 7 of 8
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Fixed |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
php8.4 | Not in release | Not in release | Not in release | — |
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log...
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Not affected |
php7.4 | Not in release | Not in release | Not affected | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | Not in release | Not in release | Not in release | — |
php7.0 | Not in release | Not in release | Not in release | — |
php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
php7.4 | Not in release | Not in release | Fixed | — |
php8.1 | Not in release | Fixed | Not in release | — |
php8.3 | Fixed | Not in release | Not in release | — |