5
CVSSv2

CVE-2020-7067

Published: 27/04/2020 Updated: 16/05/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

tenable tenable.sc

oracle communications diameter signaling router

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or potentially the execution of arbitrary code For the stable distribution (buster), these problems have been fixed in version 7319-1~deb10u1 We recommend that you upgrade your ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or potentially the execution of arbitrary code For the oldstable distribution (stretch), these problems have been fixed in version 7033-0+deb9u8 We recommend that you upgrade yo ...
In PHP versions 72x below 729, 73x below 7316 and 74x below 7434, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory This could potentially lead to information disclosure or crash (CVE-2020-7064) In PHP versions 72x below 7229, 73x below ...
In PHP versions 72x below 729, 73x below 7316 and 74x below 7434, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory This could potentially lead to information disclosure or crash (CVE-2020-7064) In PHP versions 73x below 7316 and 74x be ...
Tenablesc leverages third-party software to help provide underlying functionality Multiple third-party components were found to contain vulnerabilities, and updated versions have been made available by the providers Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of the ...

Github Repositories

Search a CVE based on a product name and version

Search CVE Search a CVE based on a product name and version Installation python3 -m venv venv source venv/bin/activate pip install -r requirementstxt Update the CVE database with the following command: python mainpy update Download db files from nvdnistgov/ downloading year 2002 to nvdcve-10-2002json downloadi