Search CVE reports


Toggle filters

71 – 80 of 259 results


CVE-2019-9025

Medium priority
Not affected

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which...

4 affected packages

php7.2, php7.3, php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.2 Not affected
php7.3 Not in release
php5 Not in release
php7.0 Not in release
Show less packages

CVE-2019-9024

Medium priority
Fixed

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas...

4 affected packages

php5, php7.0, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Fixed
php7.3 Not in release
Show less packages

CVE-2019-9023

Medium priority
Fixed

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied...

4 affected packages

php5, php7.0, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Fixed
php7.3 Not in release
Show less packages

CVE-2019-9022

Medium priority
Fixed

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations...

4 affected packages

php7.3, php5, php7.0, php7.2

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.3 Not in release
php5 Not in release
php7.0 Not in release
php7.2 Fixed
Show less packages

CVE-2019-9021

Medium priority
Fixed

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or...

4 affected packages

php7.0, php5, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0 Not in release
php5 Not in release
php7.2 Fixed
php7.3 Not in release
Show less packages

CVE-2019-9020

Medium priority
Fixed

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read...

4 affected packages

php5, php7.0, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Fixed
php7.3 Not in release
Show less packages

CVE-2019-6978

Low priority
Fixed

The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.

5 affected packages

php7.0, libgd2, php5, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0 Not in release Not in release
libgd2 Not affected Fixed
php5 Not in release Not in release
php7.2 Not in release Not affected
php7.3 Not in release Not in release
Show less packages

CVE-2019-6977

Medium priority
Fixed

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based...

5 affected packages

libgd2, php5, php7.0, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2 Fixed
php5 Not in release
php7.0 Not in release
php7.2 Not affected
php7.3 Not in release
Show less packages

CVE-2019-13224

Medium priority

Some fixes available 16 of 41

A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression....

8 affected packages

libonig, groonga, libevhtp, mudlet, php5...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libonig Fixed Fixed Fixed Fixed
groonga Vulnerable Vulnerable Vulnerable Vulnerable
libevhtp Not affected Not affected Not affected Not affected
mudlet Not in release Not in release Vulnerable Vulnerable
php5 Not in release Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Not in release
php7.2 Not in release Not in release Not in release Not affected
php7.3 Not in release Not in release Not in release Not in release
Show all 8 packages Show less packages

CVE-2019-11050

Low priority
Fixed

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to...

4 affected packages

php5, php7.0, php7.2, php7.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release
php7.0 Not in release
php7.2 Fixed
php7.3 Not in release
Show less packages