6.4
CVSSv2

CVE-2020-7060

Published: 10/02/2020 Updated: 01/07/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that PHP incorrectly handled certain scripts. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM and Ubuntu 16.04 LTS. (CVE-2015-9253)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

tenable tenable.sc

oracle communications diameter signaling router

opensuse leap 15.1

debian debian linux 8.0

Vendor Advisories

Synopsis Moderate: rh-php73-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php73-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Synopsis Moderate: php:73 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the php:73 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Several security issues were fixed in PHP ...
USN-4279-1 introduced a regression in PHP ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or incorrect validation of path names For the stable distribution (buster), these problems have been fixed in version 7314-1~deb10u1 We recommend that you upgrade your php73 pa ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or incorrect validation of path names For the oldstable distribution (stretch), these problems have been fixed in version 7033-0+deb9u7 We recommend that you upgrade your php70 ...
When using fgetss() function to read data with stripping tags, in PHP versions 72x below 7227, 73x below 7314 and 74x below 742 it is possible to supply data that will cause this function to read past the allocated buffer This may lead to information disclosure or crash (CVE-2020-7059) When using certain mbstring functions to convert ...
When using fgetss() function to read data with stripping tags, in PHP versions 72x below 7227, 73x below 7314 and 74x below 742 it is possible to supply data that will cause this function to read past the allocated buffer This may lead to information disclosure or crash (CVE-2020-7059) When using certain mbstring functions to convert ...
Tenablesc leverages third-party software to help provide underlying functionality Multiple third-party components were found to contain vulnerabilities, and updated versions have been made available by the providers Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of the ...