Search CVE reports


Toggle filters

31 – 37 of 37 results


CVE-2017-11143

Medium priority

Some fixes available 1 of 2

In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty...

3 affected packages

php5, php7.0, php7.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
php7.0
php7.1
Show less packages

CVE-2017-11142

Low priority
Ignored

In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.

3 affected packages

php5, php7.0, php7.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
php7.0
php7.1
Show less packages

CVE-2016-10712

Low priority
Fixed

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri...

3 affected packages

php7.0, php5, php7.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.0 Not in release
php5 Not in release
php7.1 Not in release
Show less packages

CVE-2016-10397

Medium priority

Some fixes available 1 of 2

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated...

3 affected packages

php5, php7.0, php7.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
php7.0
php7.1
Show less packages

CVE-2016-10168

Medium priority
Fixed

Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

4 affected packages

libgd2, php5, php7.0, php7.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2
php5
php7.0
php7.1
Show less packages

CVE-2016-10167

Medium priority
Fixed

The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

4 affected packages

libgd2, php5, php7.0, php7.1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2
php5
php7.0
php7.1
Show less packages

CVE-2015-8994

Low priority
Fixed

An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28 or 7.x after 7.0.13, the issue is resolved in a non-default configuration with...

3 affected packages

php7.1, php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php7.1
php5
php7.0
Show less packages