Search CVE reports
11 – 20 of 37 results
Some fixes available 7 of 10
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during regular expression compilation. Invalid handling of...
4 affected packages
libonig, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libonig | — | — | — | Fixed |
php5 | — | — | — | Not in release |
php7.0 | — | — | — | Not in release |
php7.1 | — | — | — | Not in release |
Some fixes available 7 of 10
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular expression compilation due to an...
4 affected packages
php7.1, libonig, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php7.1 | — | — | — | Not in release |
libonig | — | — | — | Fixed |
php5 | — | — | — | Not in release |
php7.0 | — | — | — | Not in release |
Some fixes available 7 of 10
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in mbc_enc_len() during regular expression searching. Invalid handling...
4 affected packages
libonig, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libonig | — | — | — | Fixed |
php5 | — | — | — | Not in release |
php7.0 | — | — | — | Not in release |
php7.1 | — | — | — | Not in release |
Some fixes available 7 of 10
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write or read occurs in next_state_val() during regular expression compilation....
4 affected packages
libonig, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libonig | — | — | — | Fixed |
php5 | — | — | — | Not in release |
php7.0 | — | — | — | Not in release |
php7.1 | — | — | — | Not in release |
Some fixes available 1 of 3
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during...
4 affected packages
php7.1, libonig, php5, php7.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php7.1 | — | — | — | Not in release |
libonig | — | — | — | Fixed |
php5 | — | — | — | Not in release |
php7.0 | — | — | — | Not in release |
Some fixes available 7 of 10
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during regular expression searching. A logical error...
4 affected packages
libonig, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libonig | — | — | — | Fixed |
php5 | — | — | — | Not in release |
php7.0 | — | — | — | Not in release |
php7.1 | — | — | — | Not in release |
The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image...
4 affected packages
libgd2, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libgd2 | — | — | — | — |
php5 | — | — | — | — |
php7.0 | — | — | — | — |
php7.1 | — | — | — | — |
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use...
3 affected packages
php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | — | — | — | — |
php7.0 | — | — | — | — |
php7.1 | — | — | — | — |
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor...
3 affected packages
php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php5 | — | — | — | — |
php7.0 | — | — | — | — |
php7.1 | — | — | — | — |
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
4 affected packages
libgd2, php5, php7.0, php7.1
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libgd2 | — | — | — | — |
php5 | — | — | — | — |
php7.0 | — | — | — | — |
php7.1 | — | — | — | — |