5
CVSSv2

CVE-2021-21705

Published: 04/10/2021 Updated: 29/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A security issue was found in the php_url_parse_ex() function in PHP prior to 8.0.8 and 7.4.21, which leads to FILTER_VALIDATE_URL accepting URLs with invalid userinfo, a different issue from CVE-2020-7071.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

netapp clustered data ontap -

oracle sd-wan aware 8.2

Vendor Advisories

Debian Bug report logs - #990575 php80: CVE-2021-21704 CVE-2021-21705 Package: src:php80; Maintainer for src:php80 is Debian PHP Maintainers <team+pkg-php@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 2 Jul 2021 13:06:02 UTC Severity: grave Tags: security, upstream Found i ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result an SSRF bypass of the FILTER_VALIDATE_URL check and denial of service or potentially the execution of arbitrary code in the Firebird PDO For the stable distribution (buster), these problems have been fixed in version 7329-1 ...
Several flaws has been found in php The pdo_firebase module does not check the length of the server version string in a response packet causing a stack buffer overflow, does not verify the data and uses the wrong type to cast length leading to a crash, and does not validate the response before calculation of the exec procedure leading to a crash ...
Several flaws has been found in php The pdo_firebase module does not check the length of the server version string in a response packet causing a stack buffer overflow, does not verify the data and uses the wrong type to cast length leading to a crash, and does not validate the response before calculation of the exec procedure leading to a crash ...
A security issue was found in the php_url_parse_ex() function in PHP before versions 808 and 7421, which leads to FILTER_VALIDATE_URL accepting URLs with invalid userinfo, a different issue from CVE-2020-7071 ...
Tenablesc leverages third-party software to help provide underlying functionality Multiple third-party components were found to contain vulnerabilities, and updated versions have been made available by the providers Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of the ...