Search CVE reports


Toggle filters

11 – 20 of 30 results


CVE-2025-1217

Medium priority

Some fixes available 8 of 9

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Fixed
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2024-11235

Medium priority

Some fixes available 6 of 8

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout...

7 affected packages

php8.4, php5, php7.0, php7.2, php7.4...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php8.4 Not in release Not in release Not in release
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show all 7 packages Show less packages

CVE-2024-11233

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead...

6 affected packages

php8.3, php5, php7.0, php7.2, php7.4, php8.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php8.3 Fixed Not in release Not in release
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
Show less packages

CVE-2024-11236

Medium priority

Some fixes available 6 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Fixed
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-11234

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and...

6 affected packages

php8.3, php5, php7.0, php7.2, php7.4, php8.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php8.3 Fixed Not in release Not in release
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
Show less packages

CVE-2024-8929

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-8932

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

6 affected packages

php7.0, php5, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0 Not in release Not in release Not in release
php5 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-8926

Medium priority
Not affected

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for  CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Not affected
php7.4 Not in release Not in release Not affected
php8.1 Not in release Not affected Not in release
php8.3 Not affected Not in release Not in release
Show less packages

CVE-2024-9026

Medium priority
Fixed

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Not affected
php7.4 Not in release Not in release Not affected
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-8927

Medium priority
Fixed

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of...

6 affected packages

php8.1, php5, php7.0, php7.2, php7.4, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php8.1 Not in release Fixed Not in release
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Fixed
php7.4 Not in release Not in release Fixed
php8.3 Fixed Not in release Not in release
Show less packages