Search CVE reports


Toggle filters

1 – 10 of 119 results


CVE-2025-1861

Medium priority
Needs evaluation

There is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per https://www.rfc-editor.org/rfc/rfc9110#name-uri-references, the limit is recommended to 8000. The browser...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Needs evaluation
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Needs evaluation
php8.1 Not in release Needs evaluation Not in release
php8.3 Needs evaluation Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2025-1736

Medium priority
Needs evaluation

Currently the header check in check_has_header does not verify \r which could potentially lead to some misbehaviour if only \n is used in the header value. If this value is provided by user and not checked properly (e.g. it can be...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Needs evaluation
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Needs evaluation
php8.1 Not in release Needs evaluation Not in release
php8.3 Needs evaluation Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2025-1734

Medium priority
Needs evaluation

Streams HTTP wrapper does not fail for headers with invalid name and no colon.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Needs evaluation
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Needs evaluation
php8.1 Not in release Needs evaluation Not in release
php8.3 Needs evaluation Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2025-1219

Medium priority
Needs evaluation

When requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Needs evaluation
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Needs evaluation
php8.1 Not in release Needs evaluation Not in release
php8.3 Needs evaluation Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2025-1217

Medium priority
Needs evaluation

The header parser of the http stream wrapper does not handle folded headers and passes incorrect MIME types to an attached stream notifier.

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Needs evaluation
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Needs evaluation
php8.1 Not in release Needs evaluation Not in release
php8.3 Needs evaluation Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2024-11235

Medium priority
Needs evaluation

Exception handler frees variables via cleanup_live_vars for termination. However, the subsequent php_request_shutdown performs reference counting on these variables using zend_gc_refcount(read) and zend_gc_delref(write), resulting...

7 affected packages

php5, php7.0, php7.2, php7.4, php8.1...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Needs evaluation
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Needs evaluation
php8.1 Not in release Needs evaluation Not in release
php8.3 Needs evaluation Not in release Not in release
php8.4 Not in release Not in release Not in release
Show all 7 packages Show less packages

CVE-2024-11233

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Fixed
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-11236

Medium priority

Some fixes available 6 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Fixed
php7.2 Not in release Not in release Not in release Fixed
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-11234

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and “request_fulluri” option, the URI is not properly sanitized which can lead to HTTP request smuggling and...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Fixed
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages

CVE-2024-8929

Medium priority

Some fixes available 5 of 7

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other...

6 affected packages

php5, php7.0, php7.2, php7.4, php8.1, php8.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
php5 Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Fixed
php7.2 Not in release Not in release Not in release Needs evaluation
php7.4 Not in release Not in release Fixed
php8.1 Not in release Fixed Not in release
php8.3 Fixed Not in release Not in release
Show less packages