Search CVE reports
11 – 20 of 30 results
Some fixes available 8 of 9
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may...
7 affected packages
php5, php7.0, php7.2, php7.4, php8.1...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Fixed |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
| php8.3 | Fixed | Not in release | Not in release | — |
| php8.4 | Not in release | Not in release | Not in release | — |
Some fixes available 6 of 8
In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout...
7 affected packages
php8.4, php5, php7.0, php7.2, php7.4...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php8.4 | Not in release | Not in release | Not in release | — |
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
| php8.3 | Fixed | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead...
6 affected packages
php8.3, php5, php7.0, php7.2, php7.4, php8.1
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php8.3 | Fixed | Not in release | Not in release | — |
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
Some fixes available 6 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Fixed |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
| php8.3 | Fixed | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and...
6 affected packages
php8.3, php5, php7.0, php7.2, php7.4, php8.1
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php8.3 | Fixed | Not in release | Not in release | — |
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other...
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
| php8.3 | Fixed | Not in release | Not in release | — |
Some fixes available 5 of 7
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
6 affected packages
php7.0, php5, php7.2, php7.4, php8.1, php8.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php7.0 | Not in release | Not in release | Not in release | — |
| php5 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Needs evaluation |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.1 | Not in release | Fixed | Not in release | — |
| php8.3 | Fixed | Not in release | Not in release | — |
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3...
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Not affected |
| php7.4 | Not in release | Not in release | Not affected | — |
| php8.1 | Not in release | Not affected | Not in release | — |
| php8.3 | Not affected | Not in release | Not in release | — |
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log...
6 affected packages
php5, php7.0, php7.2, php7.4, php8.1, php8.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Not affected |
| php7.4 | Not in release | Not in release | Not affected | — |
| php8.1 | Not in release | Fixed | Not in release | — |
| php8.3 | Fixed | Not in release | Not in release | — |
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of...
6 affected packages
php8.1, php5, php7.0, php7.2, php7.4, php8.3
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| php8.1 | Not in release | Fixed | Not in release | — |
| php5 | Not in release | Not in release | Not in release | — |
| php7.0 | Not in release | Not in release | Not in release | — |
| php7.2 | Not in release | Not in release | Not in release | Fixed |
| php7.4 | Not in release | Not in release | Fixed | — |
| php8.3 | Fixed | Not in release | Not in release | — |