Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php php 5.5.0 vulnerabilities and exploits
(subscribe to this query)
7
CVSSv3
CVE-2017-2624
It was found that xorg-x11-server prior to 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is...
X.org Xorg-server
Debian Debian Linux 7.0
1 Github repository
6.5
CVSSv3
CVE-2015-4598
PHP prior to 5.4.42, 5.5.x prior to 5.5.26, and 5.6.x prior to 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote malicious users to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument save method or (2...
Redhat Enterprise Linux Server Eus 7.1
Redhat Enterprise Linux Hpc Node 7.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Hpc Node Eus 7.1
Redhat Enterprise Linux Workstation 7.0
Redhat Enterprise Linux Server 7.0
Php Php 5.5.25
Php Php 5.5.24
Php Php 5.6.2
Php Php 5.6.1
Php Php 5.5.18
Php Php 5.6.7
Php Php 5.6.6
Php Php 5.5.22
Php Php 5.5.21
Php Php 5.5.14
Php Php 5.5.13
Php Php 5.5.6
Php Php 5.5.5
Php Php 5.5.4
Php Php 5.6.5
Php Php 5.6.4
5.9
CVSSv3
CVE-2015-8838
ext/mysqlnd/mysqlnd.c in PHP prior to 5.4.43, 5.5.x prior to 5.5.27, and 5.6.x prior to 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle malicious users to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152...
Php Php 5.5.0
Php Php 5.5.19
Php Php 5.5.25
Php Php 5.5.16
Php Php 5.5.1
Php Php 5.5.5
Php Php 5.5.21
Php Php 5.5.17
Php Php 5.5.14
Php Php 5.5.7
Php Php 5.5.12
Php Php 5.5.6
Php Php 5.5.3
Php Php 5.5.23
Php Php 5.5.8
Php Php 5.5.24
Php Php 5.5.15
Php Php 5.5.11
Php Php 5.5.13
Php Php 5.5.4
Php Php 5.5.26
Php Php 5.5.10
NA
CVE-2024-34340
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat...
NA
CVE-2017-11146
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not an independently fixable security issue relative to CVE-2017-11145. Notes: none
NA
CVE-2015-4021
The phar_parse_tarfile function in ext/phar/tar.c in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote malicious users to cause a denial of service (i...
Redhat Enterprise Linux Hpc Node Eus 7.1
Redhat Enterprise Linux Workstation 7.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Server Eus 7.1
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Hpc Node 7.0
Apple Mac Os X
Redhat Enterprise Linux 7.0
Redhat Enterprise Linux 6.0
Php Php 5.5.0
Php Php 5.5.1
Php Php 5.5.19
Php Php 5.5.2
Php Php 5.5.4
Php Php 5.5.5
Php Php 5.6.0
Php Php 5.6.5
Php Php 5.6.6
Php Php 5.4.39
Php Php 5.5.12
Php Php 5.5.13
Php Php 5.5.22
NA
CVE-2015-4022
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow.
Redhat Enterprise Linux Server Eus 7.1
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Hpc Node 7.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Hpc Node Eus 7.1
Redhat Enterprise Linux Workstation 7.0
Php Php
Php Php 5.4.39
Php Php 5.5.0
Php Php 5.5.11
Php Php 5.5.12
Php Php 5.5.21
Php Php 5.5.22
Php Php 5.5.7
Php Php 5.5.8
Php Php 5.6.0
Php Php 5.6.8
Php Php 5.5.9
Php Php 5.5.18
Php Php 5.5.19
Php Php 5.5.3
Php Php 5.5.4
NA
CVE-2015-4024
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 allows remote malicious users to cause a denial of service (CPU consumption) via crafted form data that triggers...
Redhat Enterprise Linux 7.0
Redhat Enterprise Linux 6.0
Apple Mac Os X
Php Php 5.5.0
Php Php 5.5.1
Php Php 5.5.19
Php Php 5.5.2
Php Php 5.5.4
Php Php 5.5.5
Php Php 5.6.0
Php Php 5.6.5
Php Php 5.6.6
Php Php
Php Php 5.5.10
Php Php 5.5.11
Php Php 5.5.20
Php Php 5.5.21
Php Php 5.5.6
Php Php 5.5.7
Php Php 5.5.8
Php Php 5.6.7
Php Php 5.6.8
2 Github repositories
NA
CVE-2015-4026
The pcntl_exec implementation in PHP prior to 5.4.41, 5.5.x prior to 5.5.25, and 5.6.x prior to 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote malicious users to bypass intended extension restrictions and execute files with unexpected name...
Redhat Enterprise Linux 6.0
Redhat Enterprise Linux 7.0
Php Php 5.5.0
Php Php
Php Php 5.4.39
Php Php 5.5.11
Php Php 5.5.12
Php Php 5.5.21
Php Php 5.5.22
Php Php 5.5.8
Php Php 5.6.0
Php Php 5.6.8
Php Php 5.5.9
Php Php 5.5.18
Php Php 5.5.19
Php Php 5.5.4
Php Php 5.5.5
Php Php 5.6.4
Php Php 5.6.5
Php Php 5.5.1
Php Php 5.5.10
Php Php 5.5.2
NA
CVE-2015-3307
The phar_parse_metadata function in ext/phar/phar.c in PHP prior to 5.4.40, 5.5.x prior to 5.5.24, and 5.6.x prior to 5.6.8 allows remote malicious users to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.
Redhat Enterprise Linux Workstation 7.0
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Server Eus 7.1
Redhat Enterprise Linux Hpc Node Eus 7.1
Redhat Enterprise Linux Hpc Node 7.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux 6.0
Redhat Enterprise Linux 7.0
Apple Mac Os X
Php Php 5.5.0
Php Php 5.5.1
Php Php 5.5.19
Php Php 5.5.2
Php Php 5.5.20
Php Php 5.5.6
Php Php 5.5.7
Php Php 5.6.0
Php Php 5.6.6
Php Php 5.6.7
Php Php 5.5.9
Php Php 5.5.14
Php Php 5.5.18
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-20065
open redirect
CVE-2024-1086
path traversal
CVE-2024-29825
XXE
CVE-2024-29822
CVE-2024-20696
CVE-2024-3564
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »