PHP 4.1

Status EOLSupport 2001-12 – 2002-03Latest 4.1.2Vulnerabilities 396← All PHP versions
Critical 10.0 Unfixed
2004-06-10≤ 4.1.2

Critical 10.0 Unfixed
2003-10-15≤ 4.1.2

Critical 10.0 Unfixed
2003-10-15≤ 4.1.2

Critical 10.0 Unfixed
2004-12-22≤ 4.1.2

security flaw

Critical 10.0 Unfixed
2004-12-22≤ 4.1.2

security flaw

Critical 10.0 Unfixed
2004-12-08≤ 4.1.2

security flaw

Critical 10.0 Unfixed
2004-12-08≤ 4.1.2

Critical 10.0 Unfixed
2004-12-08≤ 4.1.2

Critical 10.0 Unfixed
2006-10-09≤ 4.1.2

security flaw

Critical 10.0 Unfixed
2007-02-13≤ 4.1.2

security flaw

Critical 10.0 Unfixed
2008-05-05≤ 4.1.2

PHP multibyte shell escape flaw

Critical 10.0 Unfixed
2008-05-05≤ 4.1.2

php: stack based buffer overflow in FastCGI SAPI

Critical 10.0 Unfixed
2011-08-25≤ 4.1.2

PHP crash in crypt() from long salt

Critical 10.0 Unfixed
2009-12-21≤ 4.1.2

php: $_SESSION usort() interruption corruption

Critical 10.0 Unfixed
2012-07-20≤ 4.1.2

php: Integer Signedness issues in _php_stream_scandir

Critical 10.0 Unfixed
2012-05-21≤ 4.1.2

php: Buffer overflow in com_print_typeinfo() by parsing certain variant types

Critical 9.8 Unfixed
2007-03-10≤ 4.1.2

Critical 9.8 Unfixed
2008-05-07≤ 4.1.2

PHP weak 64 bit random seed

Critical 9.8 Unfixed
2008-05-05≤ 4.1.2

php: buffer overflow in a CGI path translation

KEV Unfixed
2012-05-11≤ 4.1.2

php: command line arguments injection when run in CGI mode (VU#520827)

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: type confusion issue in unserialize() with various SOAP methods

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: type confusion issue in Soap Client call() method

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: type confusion issue in unserialize() with various SOAP methods

Critical 9.8 Unfixed
2016-07-25≤ 4.1.2

php: Out-of-bounds access in locale_accept_from_http

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: Out-of-bounds heap memory read in exif_read_data() caused by malformed input

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: xml_parse_into_struct() can crash when XML parser is re-used

Critical 9.8 Unfixed
2016-09-17≤ 4.1.2

php: Missing type check when unserializing SplArray

Critical 9.8 Unfixed
2016-07-25≤ 4.1.2

php: Out-of-bounds access in exif_process_IFD_in_MAKERNOTE

Critical 9.8 Unfixed
2016-08-07≤ 4.1.2

php: Use After Free Vulnerability in PHP's GC algorithm and unserialize

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: buffer overflow in handling of long link names in tar phar archives

Critical 9.8 Unfixed
2016-07-25≤ 4.1.2

php: Use after free in unserialize() with Unexpected Session Deserialization

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

Critical 9.8 Unfixed
2016-08-07≤ 4.1.2

php: Int/size_t confusion in SplFileObject::fread

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: bcpowmod accepts negative scale causing heap buffer overflow corrupting _one_ definition

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: multiple unserialization use-after-free issues

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: Incomplete Class unserialization type confusion

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: Use-after-free vulnerability in the spl_ptr_heap_insert function

Critical 9.8 Unfixed
2016-08-07≤ 4.1.2

php: Integer Overflows in mcrypt_generic() and mdecrypt_generic() resulting in heap overflows

Critical 9.8 Unfixed
2016-07-25≤ 4.1.2

php: Buffer over-read in php_url_parse_ex

Critical 9.8 Unfixed
2016-09-12≤ 4.1.2

php: select_colors write out-of-bounds

Critical 9.8 Unfixed
2017-01-04≤ 4.1.2

php: Use after free in unserialize()

Critical 9.8 Unfixed
2017-01-04≤ 4.1.2

php: Use after free in unserialize() via DateInterval::__wakeup()

Critical 9.8 Unfixed
2017-08-18≤ 4.1.2

php: buffer over-read in finish_nested_data function

Critical 9.8 Unfixed
2017-05-24≤ 4.1.2

oniguruma: Heap buffer overflow in next_state_val() during regular expression compilation

Critical 9.8 Unfixed
2017-05-24≤ 4.1.2

oniguruma: Out-of-bounds stack read in match_at() during regular expression searching

Critical 9.8 Unfixed
2018-03-01≤ 4.1.2

php: Stack-based buffer under-read in php_stream_url_wrap_http_ex() in http_fopen_wrapper.c when parsing HTTP response

Critical 9.8 Unfixed
2019-02-22≤ 4.1.2

php: Heap-based buffer over-read in PHAR reading functions

Critical 9.8 Unfixed
2019-02-22≤ 4.1.2

php: Heap-based buffer over-read in mbstring regular expression functions

Critical 9.8 Unfixed
2019-02-22≤ 4.1.2

php: Invalid memory access in function xmlrpc_decode()

Critical 9.8 Unfixed
2019-03-08≤ 4.1.2

php: Uninitialized read in exif_process_IFD_in_TIFF

Critical 9.8 Unfixed
2019-11-26≤ 4.1.2

Critical 9.8 Unfixed
2016-09-17≤ 4.1.2

php: Memory corruption when destructing deserialized object

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: OOB read in grapheme_stripos and grapheme_strpos when negative offset is used

Critical 9.8 Unfixed
2016-08-07≤ 4.1.2

php: Double free in _php_mb_regex_ereg_replace_exec

Critical 9.8 Unfixed
2016-09-12≤ 4.1.2

php: bypass __wakeup() in deserialization of an unexpected object

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: segmentation fault in Phar::convertToData on invalid file

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: use-after-free vulnerability in session deserializer

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: Double free vulnerability in error condition of format printer

Critical 9.8 Unfixed
2016-03-31≤ 4.1.2

php: Use after free in WDDX Deserialize when processing XML data

Critical 9.8 Unfixed
2016-07-25≤ 4.1.2

php: Heap buffer overflow vulnerability in simplestring_addn in simplestring.c

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: type confusion issue in unserialize() with various SOAP methods

Critical 9.8 Unfixed
2016-07-25≤ 4.1.2

php: Use after free in SNMP with GC and unserialize()

Critical 9.8 Unfixed
2016-09-17≤ 4.1.2

php: Out of bounds heap read when verifying signature of zip phar in phar_parse_zipfile

Critical 9.8 Unfixed
2016-08-07≤ 4.1.2

php: Double Free Corruption in wddx_deserialize

Critical 9.8 Unfixed
2016-08-07≤ 4.1.2

php: ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: integer overflow in ftp_genlist() resulting in heap overflow (improved fix for CVE-2015-4022)

Critical 9.8 Unfixed
2016-09-17≤ 4.1.2

php: Use after free in wddx_deserialize

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: Out-of-bounds heap memory read in exif_read_data() caused by malformed input

Critical 9.8 Unfixed
2016-05-16≤ 4.1.2

php: exception:: getTraceAsString type confusion issue after unserialize

Critical 9.8 Unfixed
2016-05-22≤ 4.1.2

php: OOB read in grapheme_stripos and grapheme_strpos when negative offset is used

Critical 9.8 Unfixed
2017-05-12≤ 4.1.2

php: Overflowing the length of string causes crash

Critical 9.8 Unfixed
2017-01-04≤ 4.1.2

php: Invalid read when wddx decodes empty boolean element

Critical 9.8 Unfixed
2017-01-04≤ 4.1.2

php: stack buffer overflow in locale_get_display_name

Critical 9.3 Unfixed
2006-08-31≤ 4.1.2

security flaw

Critical 9.3 Unfixed
2006-03-07≤ 4.1.2

Critical 9.3 Unfixed
2006-08-31≤ 4.1.2

Critical 9.3 Unfixed
2006-06-14≤ 4.1.2

security flaw

Critical 9.3 Unfixed
2007-05-24≤ 4.1.2

Critical 9.1 Unfixed
2016-01-19≤ 4.1.2

php: Out-of-bounds memory read via gdImageRotateInterpolated

Critical 9.1 Unfixed
2017-07-10≤ 4.1.2

php: Out-of-bounds read in phar_parse_pharfile

Critical 9.1 Unfixed
2016-08-07≤ 4.1.2

php: out-of-bounds write in fpm_log.c

High 8.8 Unfixed
2016-08-07≤ 4.1.2

gd: Integer overflow in _gd2GetHeader() resulting in heap overflow

High 8.8 Unfixed
2016-08-07≤ 4.1.2

gd: Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow

High 8.8 Unfixed
2018-04-29≤ 4.1.2

php: Out-of-bounds read in ext/exif/exif.c:exif_read_data() when reading crafted JPEG data

High 8.8 Unfixed
2019-01-27≤ 4.1.2

gd: Heap-based buffer overflow in gdImageColorMatch() in gd_color_match.c

High 8.8 Unfixed
2016-07-25≤ 4.1.2

php: Stack-based buffer overflow vulnerability in php_stream_zip_opener

High 8.8 Unfixed
2016-05-22≤ 4.1.2

php: Uninitialized pointer in phar_make_dirstream()

High 8.8 Unfixed
2016-05-22≤ 4.1.2

php: use of uninitialized pointer in PharFileInfo::getContent

High 8.6 Unfixed
2016-08-07≤ 4.1.2

php: improper nul termination leading to out-of-bounds read in get_icu_value_internal

High 8.6 Unfixed
2016-08-07≤ 4.1.2

php: Integer overflow in php_filter_full_special_chars

High 8.6 Unfixed
2016-08-07≤ 4.1.2

php: Integer overflow in php_html_entities()

High 8.6 Unfixed
2016-08-07≤ 4.1.2

php: Integer underflow causing arbitrary null write in fread/gzread

High 8.2 Unfixed
2016-03-31≤ 4.1.2

php: Out-of-bounds read in phar_parse_zipfile()

High 8.1 Unfixed
2016-09-17≤ 4.1.2

php: Heap overflow in mysqlnd when not receiving UNSIGNED_FLAG in BIT field

High 8.1 Unfixed
2016-07-12≤ 4.1.2

High 7.8 Unfixed
2007-10-26≤ 4.1.2

High 7.8 Unfixed
2007-03-14≤ 4.1.2

High 7.8 Unfixed
2007-04-06≤ 4.1.2

High 7.8 Unfixed
2007-03-28≤ 4.1.2

security flaw

High 7.8 Unfixed
2016-07-25≤ 4.1.2

php: Integer overflow leads to buffer overflow in virtual_file_ex

High 7.8 Unfixed
2017-07-25≤ 4.1.2

php: Stack based 1-byte buffer over-write in zend_ini_do_op() function Zend/zend_ini_parser.c

High 7.8 Unfixed
2017-04-21≤ 4.1.2

php: Improper error handling in bzread()

High 7.6 Unfixed
2016-08-07≤ 4.1.2

gd: incorrect boundary adjustment in _gdContributionsCalc

High 7.5
2002-06-25≥ 4.1.0 and ≤ 4.1.1

security flaw

High 7.5
2002-06-25< 4.1.1

security flaw

High 7.5 Unfixed
2002-05-03≤ 4.1.2

High 7.5 Unfixed
2003-03-27≤ 4.1.2

High 7.5 Unfixed
2004-09-01≤ 4.1.2

security flaw

High 7.5 Unfixed
2004-09-01≤ 4.1.2

security flaw

High 7.5 Unfixed
2005-11-01≤ 4.1.2

security flaw

High 7.5 Unfixed
2005-11-01≤ 4.1.2

High 7.5 Unfixed
2005-11-01≤ 4.1.2

CVE-2005-3391 Two PHP safemode bypass issues (CVE-2005-3392)

High 7.5 Unfixed
2006-08-29≤ 4.1.2

High 7.5 Unfixed
2007-03-06≤ 4.1.2

security flaw

High 7.5 Unfixed
2007-04-06≤ 4.1.2

High 7.5 Unfixed
2007-08-29≤ 4.1.2

High 7.5 Unfixed
2007-03-27≤ 4.1.2

High 7.5 Unfixed
2007-02-13≤ 4.1.2

High 7.5 Unfixed
2007-09-04≤ 4.1.2

High 7.5 Unfixed
2007-09-04≤ 4.1.2

High 7.5 Unfixed
2007-04-06≤ 4.1.2

High 7.5 Unfixed
2007-04-06≤ 4.1.2

High 7.5 Unfixed
2007-09-04≤ 4.1.2

php zend_alter_ini_entry() memory_limit interruption

High 7.5 Unfixed
2007-02-13≤ 4.1.2

security flaw

High 7.5 Unfixed
2007-03-10≤ 4.1.2

High 7.5 Unfixed
2007-04-06≤ 4.1.2

High 7.5 Unfixed
2008-01-08≤ 4.1.2

High 7.5 Unfixed
2007-03-12≤ 4.1.2

High 7.5 Unfixed
2007-04-02≤ 4.1.2

php imap_mail_compose() buffer overflow via type.parameters

High 7.5 Unfixed
2007-09-12≤ 4.1.2

High 7.5 Unfixed
2007-09-04≤ 4.1.2

php size calculation in chunk_split

High 7.5 Unfixed
2007-09-04≤ 4.1.2

php money_format format string issue

High 7.5 Unfixed
2007-09-04≤ 4.1.2

High 7.5 Unfixed
2007-10-12≤ 4.1.2

High 7.5 Unfixed
2007-09-04≤ 4.1.2

High 7.5 Unfixed
2007-03-30≤ 4.1.2

High 7.5 Unfixed
2006-11-04≤ 4.1.2

PHP buffer overflow

High 7.5 Unfixed
2007-08-30≤ 4.1.2

High 7.5 Unfixed
2007-05-09≤ 4.1.2

php libxmlrpc library overflow

High 7.5 Unfixed
2007-02-13≤ 4.1.2

security flaw

High 7.5 Unfixed
2009-11-27≤ 4.1.2

php: proc_open() safe mode restriction bypass

High 7.5 Unfixed
2009-09-22≤ 4.1.2

php: openssl extension: Incorrect verification of SSL certificate with NUL in name

High 7.5 Unfixed
2009-09-22≤ 4.1.2

php: gd - improper upper bound check in imagecolortransparent

High 7.5 Unfixed
2009-09-22≤ 4.1.2

php: exif extension: Multiple missing sanity checks in EXIF file processing

High 7.5 Unfixed
2008-12-17≤ 4.1.2

php: ZipArchive:: extractTo() Directory Traversal Vulnerability

High 7.5 Unfixed
2008-12-17≤ 4.1.2

php: incorrect php_value order for Apache configuration

High 7.5 Unfixed
2008-05-07≤ 4.1.2

PHP 32 bit weak random seed

High 7.5 Unfixed
2011-03-15≤ 4.1.2

php: integer overflow in shmop_read()

High 7.5 Unfixed
2011-03-16≤ 4.1.2

php: several format string vulnerabilities in PHP's Phar extension

High 7.5 Unfixed
2011-03-18≤ 4.1.2

php: use-after-free vulnerability in substr_replace()

High 7.5 Unfixed
2012-05-11≤ 4.1.2

php: incomplete CVE-2012-1823 fix - incorrect check for =

High 7.5 Unfixed
2013-03-06≤ 4.1.2

php53: Arbitrary locations file write due absent validation of soap.wsdl_cache_dir configuration directive value

High 7.5 Unfixed
2013-12-17≤ 4.1.2

php: memory corruption in openssl_x509_parse()

High 7.5 Unfixed
2012-07-07≤ 4.1.2

php: Integer overflow leading to heap-buffer overflow in the Phar extension

High 7.5 Unfixed
2014-11-23≤ 4.1.2

php: xmlrpc ISO8601 date format parsing buffer overflow

High 7.5 Unfixed
2015-03-30≤ 4.1.2

php: use after free in opcache extension

High 7.5 Unfixed
2014-10-29≤ 4.1.2

php: integer overflow in unserialize()

High 7.5 Unfixed
2014-12-20≤ 4.1.2

php: use after free vulnerability in unserialize()

High 7.5 Unfixed
2014-12-31≤ 4.1.2

php: Double-free in zend_ts_hash_graceful_destroy()

High 7.5 Unfixed
2015-03-30≤ 4.1.2

php: use after free vulnerability in unserialize() with DateTimeZone

High 7.5 Unfixed
2015-03-30≤ 4.1.2

libzip: integer overflow when processing ZIP archives

High 7.5 Unfixed
2015-01-27≤ 4.1.2

php: use after free vulnerability in unserialize() (incomplete fix of CVE-2014-8142)

High 7.5 Unfixed
2015-03-30≤ 4.1.2

php: use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re

High 7.5 Unfixed
2015-03-30≤ 4.1.2

php: heap buffer overflow in enchant_broker_request_dict()

High 7.5 Unfixed
2015-03-30≤ 4.1.2

file: malformed elf file causes access to uninitialized memory

High 7.5 Unfixed
2014-07-09≤ 4.1.2

php: unserialize() SPL ArrayObject / SPLObjectStorage type confusion flaw

High 7.5 Unfixed
2015-01-03≤ 4.1.2

php: out of bounds read when parsing a crafted .php file

High 7.5 Unfixed
2016-05-16≤ 4.1.2

php: denial of service when processing a crafted file with Fileinfo

High 7.5 Unfixed
2016-05-16≤ 4.1.2

php: denial of service when processing a crafted file with Fileinfo

High 7.5 Unfixed
2016-05-20≤ 4.1.2

php: Integer overflow in php_raw_url_encode

High 7.5 Unfixed
2015-06-09≤ 4.1.2

php: integer overflow leading to heap overflow when reading FTP file listing

High 7.5 Unfixed
2016-01-19≤ 4.1.2

php: Files from archive can be extracted outside of destination directory using phar

High 7.5 Unfixed
2015-06-09≤ 4.1.2

php: SoapClient's __call() type confusion through unserialize()

High 7.5 Unfixed
2015-06-09≤ 4.1.2

php: invalid pointer free() in phar_tar_process_metadata()

High 7.5 Unfixed
2016-09-12≤ 4.1.2

php: wddx_deserialize null dereference in php_wddx_pop_element

High 7.5 Unfixed
2016-09-12≤ 4.1.2

php: wddx_deserialize null dereference

High 7.5 Unfixed
2016-05-16≤ 4.1.2

file: root_storage NULL pointer deference flaw in CDF parser

High 7.5 Unfixed
2016-05-16≤ 4.1.2

php: NULL pointer dereference in XSLTProcessor class

High 7.5 Unfixed
2016-05-16≤ 4.1.2

php: NULL pointer dereference in XSLTProcessor class

High 7.5 Unfixed
2016-09-17≤ 4.1.2

php: Null pointer dereference in php_wddx_push_element

High 7.5 Unfixed
2016-09-12≤ 4.1.2

php: Session Data Injection Vulnerability

High 7.5 Unfixed
2017-01-04≤ 4.1.2

gd: Stack overflow in gdImageFillToBorder on truecolor images

High 7.5 Unfixed
2017-07-10≤ 4.1.2

php: Incorrect return value check of OpenSSL sealing function leads to crash

High 7.5 Unfixed
2017-07-10≤ 4.1.2

php: Incorrect WDDX deserialization of boolean parameters leads to DoS

High 7.5 Unfixed
2017-07-10≤ 4.1.2

php: Denial-of-Service via injecting long form variables

High 7.5 Unfixed
2017-11-07≤ 4.1.2

php: Out-of-bound read in timelib_meridian()

High 7.5 Unfixed
2017-07-10≤ 4.1.2

php: wddx_deserialize() heap out-of-bound read via php_parse_date()

High 7.5 Unfixed
2017-07-10≤ 4.1.2

php: Incorrect handling of URI components in URL parser

High 7.5 Unfixed
2018-02-09≤ 4.1.2

php: Output of stream_get_meta_data can be falsified by its input

High 7.5 Unfixed
2018-04-29≤ 4.1.2

php: Infinite loop in ext/iconv/iconv.c when using stream filter with convert.incov on invalid sequence leads to denial-of-service

High 7.5 Unfixed
2018-04-29≤ 4.1.2

php: NULL pointer dereference due to mishandling of ldap_get_dn return value allows DoS via malicious LDAP server reply

High 7.5 Unfixed
2019-02-21≤ 4.1.2

php: Buffer over-read in PHAR reading functions

High 7.5 Unfixed
2019-02-22≤ 4.1.2

php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c

High 7.5 Unfixed
2018-08-07≤ 4.1.2

High 7.5 Unfixed
2018-08-03≤ 4.1.2

php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()

High 7.5 Unfixed
2019-03-08≤ 4.1.2

php: File rename across filesystems may allow unwanted access during processing

High 7.5 Unfixed
2019-03-08≤ 4.1.2

php: Uninitialized read in exif_process_IFD_in_MAKERNOTE

High 7.5 Unfixed
2019-03-08≤ 4.1.2

php: Uninitialized read in exif_process_IFD_in_MAKERNOTE

High 7.5 Unfixed
2015-06-09≤ 4.1.2

php: buffer overflow in phar_set_inode()

High 7.5 Unfixed
2016-05-22≤ 4.1.2

gd: gdImageScaleTwoPass function in gd_interpolation.c uses inconsistent allocate and free approaches

High 7.5 Unfixed
2015-06-09≤ 4.1.2

php: regressions in 5.4+

High 7.5 Unfixed
2016-05-22≤ 4.1.2

php: odbc_bindcols function mishandles driver behavior for SQL_WVARCHAR columns

High 7.5 Unfixed
2016-09-12≤ 4.1.2

php: wddx_deserialize null dereference with invalid xml

High 7.5 Unfixed
2016-05-16≤ 4.1.2

gd: gdImageFillToBorder deep recursion leading to stack overflow

High 7.5 Unfixed
2015-06-09≤ 4.1.2

php: pcntl_exec() accepts paths with NUL character

High 7.5 Unfixed
2016-09-17≤ 4.1.2

php: Stack based buffer overflow in msgfmt_format_message

High 7.5 Unfixed
2016-05-16≤ 4.1.2

php: Stack consumption vulnerability in Zend/zend_exceptions.c

High 7.5 Unfixed
2016-05-16≤ 4.1.2

php: NULL pointer dereference in php_pgsql_meta_data()

High 7.5 Unfixed
2017-01-24≤ 4.1.2

php: Out-of-bounds heap read on unserialize in finish_nested_data()

High 7.5 Unfixed
2017-04-19≤ 4.1.2

High 7.5 Unfixed
2017-01-24≤ 4.1.2

php: Integer overflow in phar_parse_pharfile

High 7.5 Unfixed
2017-01-04≤ 4.1.2

php: NULL Pointer Dereference in WDDX Packet Deserialization with PDORow

High 7.5 Unfixed
2017-01-24≤ 4.1.2

php: Wrong calculation in exif_convert_any_to_int function

High 7.4 Unfixed
2017-03-27≤ 4.1.2

php: potential SSRF via fsockopen

High 7.3 Unfixed
2014-12-31≤ 4.1.2

php: denial of service in libmagic/apprentice.c

High 7.3 Unfixed
2016-01-19≤ 4.1.2

php: Use After Free Vulnerability in unserialize()

High 7.3 Unfixed
2016-01-19≤ 4.1.2

php: buffer overflow and stack smashing error in phar_fix_filepath

High 7.3 Unfixed
2016-05-20≤ 4.1.2

file: Buffer over-write in finfo_open with malformed magic file

High 7.3 Unfixed
2016-01-19≤ 4.1.2

php: dangling pointer in the unserialization of ArrayObject items

High 7.3 Unfixed
2016-01-19≤ 4.1.2

php: SOAP serialize_function_call() type confusion

High 7.2 Unfixed
2007-05-09≤ 4.1.2

php user_filter_factory_create overflow

High 7.2 Unfixed
2006-11-04≤ 4.1.2

High 7.1 Unfixed
2016-05-16≤ 4.1.2

php: Type confusion vulnerability in make_http_soap_request()

Medium 6.9 Unfixed
2007-11-20≤ 4.1.2

Medium 6.8 Unfixed
2004-07-16≤ 4.1.2

security flaw

Medium 6.8 Unfixed
2007-04-06≤ 4.1.2

Medium 6.8 Unfixed
2007-03-21≤ 4.1.2

security flaw

Medium 6.8 Unfixed
2007-03-10≤ 4.1.2

Medium 6.8 Unfixed
2007-03-06≤ 4.1.2

security flaw

Medium 6.8 Unfixed
2007-09-14≤ 4.1.2

Medium 6.8 Unfixed
2007-03-20≤ 4.1.2

Medium 6.8 Unfixed
2007-03-10≤ 4.1.2

Medium 6.8 Unfixed
2007-09-04≤ 4.1.2

php multiple integer overflows in gd

Medium 6.8 Unfixed
2007-06-29≤ 4.1.2

Medium 6.8 Unfixed
2007-04-06≤ 4.1.2

security flaw

Medium 6.8 Unfixed
2007-06-04≤ 4.1.2

php chunk_split integer overflow

Medium 6.8 Unfixed
2007-03-21≤ 4.1.2

Medium 6.8 Unfixed
2011-01-18≤ 4.1.2

php: Zend use-after-free certain methods are called on objects accessed by a reference

Medium 6.8 Unfixed
2010-11-12≤ 4.1.2

php: XSS and SQL injection bypass via crafted overlong UTF-8 encoded string

Medium 6.8 Unfixed
2012-02-10≤ 4.1.2

php: PG(magic_quote_gpc) was not restored on shutdown

Medium 6.8 Unfixed
2010-11-12≤ 4.1.2

php: XSS mitigation bypass via utf8_decode()

Medium 6.8 Unfixed
2013-08-13≤ 4.1.2

php: session fixation vulnerability allows remote hijacking of sessions

Medium 6.8 Unfixed
2014-10-29≤ 4.1.2

php: heap corruption issue in exif_thumbnail()

Medium 6.8 Unfixed
2014-08-23≤ 4.1.2

php: multiple buffer over-reads in php_parserr

Medium 6.8 Unfixed
2014-02-18≤ 4.1.2

php: multiple vulnerabilities in gdImageCrop()

Medium 6.8 Unfixed
2015-01-27≤ 4.1.2

php: Free called on unitialized pointer in exif.c

Medium 6.8 Unfixed
2015-06-09≤ 4.1.2

php: pipelined request executed in deinitialized interpreter under httpd 2.4

Medium 6.8 Unfixed
2015-12-11≤ 4.1.2

php: uninitialized pointer in phar_make_dirstream()

Medium 6.8 Unfixed
2015-12-11≤ 4.1.2

php: NULL pointer dereference in phar_get_fp_offset()

Medium 6.5 Unfixed
2014-07-09≤ 4.1.2

file: cdf_read_short_sector insufficient boundary check

Medium 6.5 Unfixed
2014-07-09≤ 4.1.2

file: cdf_count_chain insufficient boundary check

Medium 6.5 Unfixed
2014-07-09≤ 4.1.2

file: mconvert incorrect handling of truncated pascal string size

Medium 6.5 Unfixed
2016-07-25≤ 4.1.2

php: Null pointer dereference in exif_process_user_comment

Medium 6.5 Unfixed
2017-08-02≤ 4.1.2

php: Buffer over-read from unitialized data in gdImageCreateFromGifCtx function

Medium 6.5 Unfixed
2018-02-19≤ 4.1.2

php: Infinite loop in php-fpm when restarting a child using program execution function

Medium 6.5 Unfixed
2022-09-28≤ 4.1.2

$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

Medium 6.5 Unfixed
2016-05-16≤ 4.1.2

php: missing null byte checks for paths in various PHP extensions

Medium 6.5 Unfixed
2016-05-16≤ 4.1.2

php: missing null byte checks for paths in DOM and GD extensions

Medium 6.4 Unfixed
2006-03-07≤ 4.1.2

Medium 6.4 Unfixed
2007-11-20≤ 4.1.2

php htmlentities/htmlspecialchars multibyte sequences

Medium 6.4 Unfixed
2009-08-25≤ 4.1.2

php: dba_replace() file corruption vulnerability

Medium 6.4 Unfixed
2009-12-01≤ 4.1.2

Medium 6.4 Unfixed
2012-02-02≤ 4.1.2

php: XSLT file writing vulnerability

Medium 6.4 Unfixed
2011-06-16≤ 4.1.2

php: file path injection vulnerability in RFC1867 file upload filename

Medium 6.2 Unfixed
2006-10-06≤ 4.1.2

Medium 6.1 Unfixed
2016-08-07≤ 4.1.2

php: HTTP response splitting in header() function

Medium 6.1 Unfixed
2018-01-16≤ 4.1.2

php: Reflected XSS on PHAR 404 page

Medium 6.1 Unfixed
2018-04-29≤ 4.1.2

php: Reflected XSS vulnerability on PHAR 403 and 404 error pages

Medium 6.1 Unfixed
2018-09-16≤ 4.1.2

php: Cross-site scripting (XSS) flaw in Apache2 component via body of 'Transfer-Encoding: chunked' request

Medium 5.9 Unfixed
2016-05-16≤ 4.1.2

php: mysqlnd interface vulnerable to BACKRONYM

Medium 5.8 Unfixed
2012-05-24≤ 4.1.2

php: $_FILES array indexes corruption

Medium 5.8 Unfixed
2015-06-09≤ 4.1.2

php: buffer over-read in Phar metadata parsing

Medium 5.5 Unfixed
2018-01-16≤ 4.1.2

gd: Infinite loop in gdImageCreateFromGifCtx() in gd_gif_in.c

Medium 5.5 Unfixed
2018-08-02≤ 4.1.2

php: exif: Buffer over-read in exif_process_IFD_in_MAKERNOTE()

Medium 5.4 Unfixed
2007-03-16≤ 4.1.2

Medium 5.3 Unfixed
2016-09-12≤ 4.1.2

php: Memory Leakage In exif_process_IFD_in_TIFF

Medium 5.3 Unfixed
2016-05-16≤ 4.1.2

php: missing null byte checks for paths in various PHP extensions

Medium 5.1 Unfixed
2004-07-16≤ 4.1.2

security flaw

Medium 5.1 Unfixed
2007-05-09≤ 4.1.2

php make_http_soap_request flaw

Medium 5.1 Unfixed
2007-03-10≤ 4.1.2

Medium 5.1 Unfixed
2007-03-10≤ 4.1.2

Medium 5.1 Unfixed
2008-09-18≤ 4.1.2

PHP: insecure random numbers

Medium 5.0 Unfixed
2004-10-16≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2002-05-03≤ 4.1.2

Medium 5.0 Unfixed
2006-06-14≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2003-04-02≤ 4.1.2

Medium 5.0 Unfixed
2004-09-01≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2005-06-28≤ 4.1.2

Medium 5.0 Unfixed
2005-11-18≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2006-03-29≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2005-11-01≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2005-11-29≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2007-03-10≤ 4.1.2

Medium 5.0 Unfixed
2007-02-13≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2007-05-16≤ 4.1.2

Medium 5.0 Unfixed
2007-02-13≤ 4.1.2

security flaw

Medium 5.0 Unfixed
2007-09-04≤ 4.1.2

php floating point exception inside wordwrap

Medium 5.0 Unfixed
2007-03-28≤ 4.1.2

Medium 5.0 Unfixed
2007-09-10≤ 4.1.2

php crash in glob() and fnmatch() functions

Medium 5.0 Unfixed
2007-09-10≤ 4.1.2

php crash in setlocale() function

Medium 5.0 Unfixed
2007-09-12≤ 4.1.2

Medium 5.0 Unfixed
2007-03-10≤ 4.1.2

php session extension information leak

Medium 5.0 Unfixed
2007-03-14≤ 4.1.2

Medium 5.0 Unfixed
2007-04-30≤ 4.1.2

Medium 5.0 Unfixed
2007-09-05≤ 4.1.2

php malformed cookie handling

Medium 5.0 Unfixed
2007-09-10≤ 4.1.2

Medium 5.0 Unfixed
2008-06-20≤ 4.1.2

php: chdir(), ftok() (standard ext) safe_mode bypass safe_mode bypass

Medium 5.0 Unfixed
2009-04-08≤ 4.1.2

php: crash when extracting zip file with relative paths

Medium 5.0 Unfixed
2008-12-26≤ 4.1.2

php: libgd imagerotate() array index error memory disclosure

Medium 5.0 Unfixed
2008-06-23≤ 4.1.2

php: ext/imap legacy routine buffer overflow

Medium 5.0 Unfixed
2009-11-23≤ 4.1.2

php: safe_mode / open_basedir security fixes in 5.3.1

Medium 5.0 Unfixed
2011-08-25≤ 4.1.2

PHP error_log DoS

Medium 5.0 Unfixed
2011-08-25≤ 4.1.2

crypt_blowfish: 8-bit character mishandling allows different password pairs to produce the same hash

Medium 5.0 Unfixed
2011-08-25≤ 4.1.2

php: multiple NULL pointer dereferences

Medium 5.0 Unfixed
2011-01-18≤ 4.1.2

php: iconv_mime_decode_headers skips headers using unsupported encoding

Medium 5.0 Unfixed
2011-01-18≤ 4.1.2

php: paths with NULL character were considered valid

Medium 5.0 Unfixed
2011-02-02≤ 4.1.2

php: mt_rand() does not check that max is greater than min

Medium 5.0 Unfixed
2010-12-06≤ 4.1.2

php: getSymbol() integer overflow vulnerability

Medium 5.0 Unfixed
2011-12-30≤ 4.1.2

php: hash table collisions CPU usage DoS (oCERT-2011-003)

Medium 5.0 Unfixed
2010-03-26≤ 4.1.2

php: safe_mode / open_basedir security fixes in 5.2.13/5.3.2

Medium 5.0 Unfixed
2012-02-14≤ 4.1.2

php: crash when unserializing serialized PDORow object

Medium 5.0 Unfixed
2011-03-20≤ 4.1.2

php: Crash by converting serial day numbers (SDN) into Julian calendar

Medium 5.0 Unfixed
2009-12-24≤ 4.1.2

php: DoS via unserialize

Medium 5.0 Unfixed
2012-02-14≤ 4.1.2

php: strtotime timezone memory leak

Medium 5.0 Unfixed
2011-02-02≤ 4.1.2

php: extract() can overwrite $GLOBALS and $this when using EXTR_OVERWRITE

Medium 5.0 Unfixed
2011-03-20≤ 4.1.2

php: NumberFormatter: set a symbol value crash (DoS) on bogus values

Medium 5.0 Unfixed
2012-05-11≤ 4.1.2

php: incomplete CVE-2012-1823 fix - missing filtering of -T and -h

Medium 5.0 Unfixed
2013-03-06≤ 4.1.2

php: Ability to read arbitrary files due use of external entities while parsing SOAP WSDL files

Medium 5.0 Unfixed
2013-06-21≤ 4.1.2

php: Integer overflow in SndToJewish - DoS (excessive CPU use, interpreter hang)

Medium 5.0 Unfixed
2012-07-20≤ 4.1.2

php: open_basedir bypass via SQLite functionality

Medium 5.0 Unfixed
2013-11-28≤ 4.1.2

php: heap-based buffer over-read in DateInterval

Medium 5.0 Unfixed
2013-06-21≤ 4.1.2

php: Heap-based buffer overflow in quoted_printable_encode()

Medium 5.0 Unfixed
2015-03-30≤ 4.1.2

php: NULL pointer dereference in pgsql extension

Medium 5.0 Unfixed
2014-06-01≤ 4.1.2

file: CDF property info parsing nelements infinite loop

Medium 5.0 Unfixed
2014-06-01≤ 4.1.2

file: cdf_unpack_summary_info() excessive looping DoS

Medium 5.0 Unfixed
2014-10-29≤ 4.1.2

php: xmlrpc ISO8601 date format parsing out-of-bounds read in mkgmtime()

Medium 5.0 Unfixed
2015-03-30≤ 4.1.2

file: out of bounds read in mconvert()

Medium 5.0 Unfixed
2015-03-30≤ 4.1.2

php: move_uploaded_file() NUL byte injection in file name

Medium 5.0 Unfixed
2014-02-18≤ 4.1.2

php: multiple vulnerabilities in gdImageCrop()

Medium 5.0 Unfixed
2015-06-09≤ 4.1.2

php: SoapClient's do_soap_call() type confusion after unserialize()

Medium 5.0 Unfixed
2015-06-09≤ 4.1.2

php: multipart/form-data request parsing CPU usage DoS

Medium 5.0 Unfixed
2015-06-09≤ 4.1.2

php: memory corruption in phar_parse_tarfile caused by empty entry file name

Medium 4.7 Unfixed
2018-04-29≤ 4.1.2

php: Dumpable FPM child processes allow bypassing opcache access controls

Medium 4.6 Unfixed
2006-08-08≤ 4.1.2

security flaw

Medium 4.6 Unfixed
2006-06-26≤ 4.1.2

CVE-2006-3011 multiple PHP safe mode bypasses (CVE-2006-4481, CVE-2006-2563)

Medium 4.6 Unfixed
2007-03-16≤ 4.1.2

Medium 4.6 Unfixed
2007-08-21≤ 4.1.2

Medium 4.6 Unfixed
2007-04-03≤ 4.1.2

Medium 4.6 Unfixed
2015-03-30≤ 4.1.2

php: predictable file name used for cache in world writeable directory

Medium 4.6 Unfixed
2014-07-10≤ 4.1.2

php: SPL Iterators use-after-free

Medium 4.4 Unfixed
2007-09-04≤ 4.1.2

Medium 4.4 Unfixed
2011-02-02≤ 4.1.2

Medium 4.3 Unfixed
2003-06-20≤ 4.1.2

security flaw

Medium 4.3 Unfixed
2005-11-01≤ 4.1.2

security flaw

Medium 4.3 Unfixed
2007-09-14≤ 4.1.2

Medium 4.3 Unfixed
2007-05-17≤ 4.1.2

Medium 4.3 Unfixed
2007-07-16≤ 4.1.2

php cross-site cookie insertion

Medium 4.3 Unfixed
2007-02-20≤ 4.1.2

security flaw

Medium 4.3 Unfixed
2007-11-20≤ 4.1.2

php session ID leakage

Medium 4.3 Unfixed
2009-08-05≤ 4.1.2

php: exif_read_data crash on corrupted JPEG files

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php: DoS when using HTTP proxy with the FTP wrapper

Medium 4.3 Unfixed
2009-12-21≤ 4.1.2

php: htmlspecialchars() insufficient checking of input for multi-byte encodings

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php/libzip: segfault with FL_UNCHANGED on empty archive in zip_name_locate()

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php: buffer over-read in Exif extension

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php: DoS (excessive CPU consumption) by processing certain Zip archive files

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php: crash when processing certain Zip archives

Medium 4.3 Unfixed
2011-02-02≤ 4.1.2

php: race condition when handling many concurrent signals may lead to memory corruption

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php: Crash by retrieving string value of a variable, when high precision used

Medium 4.3 Unfixed
2011-03-20≤ 4.1.2

php: Multiple memory leaks in the OpenSSL extension

Medium 4.3 Unfixed
2012-07-05≤ 4.1.2

crypt(): DES encrypted password weakness

Medium 4.3 Unfixed
2013-08-18≤ 4.1.2

php: hostname check bypassing vulnerability in SSL client

Medium 4.3 Unfixed
2013-09-16≤ 4.1.2

Medium 4.3 Unfixed
2012-08-30≤ 4.1.2

PHP: sapi_header_op() %0D sequence handling security bypass

Medium 4.3 Unfixed
2014-08-23≤ 4.1.2

file: incomplete fix for CVE-2012-1571 in cdf_read_property_info

Medium 4.3 Unfixed
2014-03-14≤ 4.1.2

file: out-of-bounds access in search rules with offsets from input file

Medium 4.3 Unfixed
2014-07-09≤ 4.1.2

file: cdf_read_property_info insufficient boundary check

Medium 4.3 Unfixed
2014-07-09≤ 4.1.2

file: cdf_check_stream_offset insufficient boundary check

Medium 4.3 Unfixed
2014-03-21≤ 4.1.2

gd: NULL pointer dereference in gdImageCreateFromXpm()

Medium 4.3 Unfixed
2016-05-22≤ 4.1.2

php: ZipArchive:: extractTo allows for directory traversal when creating directories

Low 3.6 Unfixed
2006-09-12≤ 4.1.2

CVE-2006-4625 PHP safe mode bypass

Low 3.6 Unfixed
2014-09-27≤ 4.1.2

php-pear: insecure temporary file use for cache data

Low 3.3 Unfixed
2014-06-08≤ 4.1.2

php: insecure temporary file use in the configure script

Low 3.2 Unfixed
2006-03-07≤ 4.1.2

Low 2.6 Unfixed
2006-01-13≤ 4.1.2

security flaw

Low 2.6 Unfixed
2006-04-10≤ 4.1.2

security flaw

Low 2.6 Unfixed
2007-05-09≤ 4.1.2

php CRLF injection

Low 2.6 Unfixed
2007-05-16≤ 4.1.2

Low 2.6 Unfixed
2009-01-02≤ 4.1.2

php: XSS via PHP error messages

Low 2.6 Unfixed
2012-08-06≤ 4.1.2

php: PDO array over-read crash

Low 2.3 Unfixed
2022-09-28≤ 4.1.2

phar wrapper can occur dos when using quine gzip file

Low 2.1 Unfixed
2002-06-25≤ 4.1.2

Low 2.1 Unfixed
2004-10-16≤ 4.1.2

security flaw

Low 2.1 Unfixed
2005-10-27≤ 4.1.2

Low 2.1 Unfixed
2006-06-13≤ 4.1.2

CVE-2006-2660 tempnam() unique filename bypass

Low 2.1 Unfixed
2006-04-10≤ 4.1.2

Low 2.1 Unfixed
2007-11-20≤ 4.1.2