PHP 7.1

Status EOLSupport 2016-12 – 2019-12Latest 7.1.33Vulnerabilities 84← All PHP versions
KEV Unfixed
2024-06-09≤ 7.1.33

Argument Injection in PHP-CGI

Critical 9.8
2017-01-11< 7.0.11

php: Use of uninitialized value in SplObjectStorag::unserialize

Critical 9.8
2017-05-21= 7.1.5

php: Segfault in i_zval_ptr_dtor()

Critical 9.8 Unfixed
2017-05-12≤ 7.1.33

php: Overflowing the length of string causes crash

Critical 9.8
2018-08-02< 7.1.5

php: Integer overflow in mysqli_api.c:mysqli_real_escape_string()

Critical 9.8
2017-01-04< 7.1.0

php: Use After Free in unserialize()

Critical 9.8
2017-01-24< 7.1.1

php: Off-by-one error in phar_parse_pharfile when loading crafted phar archive

Critical 9.8
2017-01-12< 7.1.1

php: Use-after-free vulnerability when resizing the 'properties' hash table of a serialized object

Critical 9.8
2017-01-11< 7.1.1

php: Use of uninitialized memory in unserialize()

Critical 9.8
2017-05-24< 7.1.7

oniguruma: Out-of-bounds heap write in bitset_set_range()

Critical 9.8
2017-05-24< 7.1.7

oniguruma: Out-of-bounds stack read in mbc_enc_len() during regular expression searching

Critical 9.8
2017-05-24< 7.1.7

oniguruma: Heap buffer overflow in next_state_val() during regular expression compilation

Critical 9.8
2017-05-24< 7.1.7

oniguruma: Out-of-bounds stack read in match_at() during regular expression searching

Critical 9.8
2017-07-17< 7.1.7

php: Stack-based buffer over-read in msgfmt_parse_message function

Critical 9.8
2017-08-18< 7.1.7

php: buffer over-read in finish_nested_data function

Critical 9.8
2017-08-18< 7.1.9

php: Heap use after free in ext/standard/var_unserializer.re

Critical 9.8
2016-01-03< 7.1.11

pcre: heap buffer overflow in handling of duplicate named groups (8.39/14)

Critical 9.8
2019-07-10< 7.1.32

oniguruma: Use-after-free in onig_new_deluxe() in regext.c

Critical 9.8
2018-03-01< 7.1.15

php: Stack-based buffer under-read in php_stream_url_wrap_http_ex() in http_fopen_wrapper.c when parsing HTTP response

Critical 9.8
2019-02-22< 7.1.26

php: Invalid memory access in function xmlrpc_decode()

Critical 9.8
2019-02-22< 7.1.26

php: Heap-based buffer over-read in PHAR reading functions

Critical 9.8
2019-02-22< 7.1.26

php: Heap-based buffer over-read in mbstring regular expression functions

Critical 9.8
2019-03-08< 7.1.27

php: Uninitialized read in exif_process_IFD_in_TIFF

Critical 9.6
2016-05-22< 7.1.13

php: libxml_disable_entity_loader setting is shared between threads

Critical 9.1
2017-07-10< 7.1.1

php: Out-of-bounds read in phar_parse_pharfile

Critical 9.1
2019-04-18< 7.1.28

Heap over-read in PHP EXIF extension

Critical 9.1
2019-04-18< 7.1.28

Heap over-read in PHP EXIF extension

Critical 9.1
2019-05-03< 7.1.29

Heap over-read in PHP EXIF extension

Critical 9.1
2019-06-18< 7.1.30

Out-of-bounds read in iconv.c

Critical 9.1
2019-06-18< 7.1.30

Heap buffer overflow in EXIF extension

High 8.8
2018-04-29< 7.1.17

php: Out-of-bounds read in ext/exif/exif.c:exif_read_data() when reading crafted JPEG data

High 8.8
2019-01-27< 7.1.26

gd: Heap-based buffer overflow in gdImageColorMatch() in gd_color_match.c

KEV
2019-10-28< 7.1.33

Underflow in PHP-FPM can lead to RCE

High 8.1
2019-03-11< 7.1.27

php: buffer overflow in ext/phar/tar.c

High 7.8
2017-07-25< 7.1.7

php: Stack based 1-byte buffer over-write in zend_ini_do_op() function Zend/zend_ini_parser.c

High 7.5 Unfixed
2017-04-19≤ 7.1.4

High 7.5
2017-04-03= 7.1.2

php: Null pointer dereference via crafted "declare(ticks="

High 7.5
2018-08-02= 7.1.5

php: Out of bounds access in php_pcre.c:php_pcre_replace_impl()

High 7.5
2017-01-04< 7.1.0

php: NULL Pointer Dereference in WDDX Packet Deserialization with PDORow

High 7.5
2017-01-04< 7.1.0

gd: Stack overflow in gdImageFillToBorder on truecolor images

High 7.5
2017-01-24< 7.1.1

php: Integer overflow in phar_parse_pharfile

High 7.5
2017-01-24< 7.1.1

php: Wrong calculation in exif_convert_any_to_int function

High 7.5
2017-01-24< 7.1.1

php: Null pointer dereference when unserializing PHP object

High 7.5
2017-01-24< 7.1.1

php: Out-of-bounds heap read on unserialize in finish_nested_data()

High 7.5
2017-07-10< 7.1.3

php: Denial-of-Service via injecting long form variables

High 7.5
2017-05-24< 7.1.7

oniguruma: Invalid pointer dereference in left_adjust_char_head()

High 7.5
2017-07-10< 7.1.7

php: Incorrect return value check of OpenSSL sealing function leads to crash

High 7.5
2017-07-10< 7.1.7

php: wddx_deserialize() heap out-of-bound read via php_parse_date()

High 7.5
2017-08-18< 7.1.7

php: heap use after free in ext/standard/var_unserializer.re

High 7.5
2017-07-10< 7.1.8

php: Incorrect WDDX deserialization of boolean parameters leads to DoS

High 7.5
2017-11-07< 7.1.11

php: Out-of-bound read in timelib_meridian()

High 7.5
2018-08-03< 7.1.13

php: Mishandled http_header_value in an atoi() call in http_fopen_wrapper.c

High 7.5
2018-04-29< 7.1.17

php: NULL pointer dereference due to mishandling of ldap_get_dn return value allows DoS via malicious LDAP server reply

High 7.5
2018-04-29< 7.1.17

php: Infinite loop in ext/iconv/iconv.c when using stream filter with convert.incov on invalid sequence leads to denial-of-service

High 7.5
2018-08-03< 7.1.20

php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()

High 7.5
2018-11-25< 7.1.25

php: imap_open() allows running arbitrary shell commands via mailbox parameter

High 7.5
2018-08-07< 7.1.20

High 7.5
2018-11-20< 7.1.24

High 7.5
2018-11-20< 7.1.24

php: Serializing or unserializing COM objects crashes

High 7.5
2018-12-07< 7.1.26

php: NULL pointer dereference in ext/imap/php_imap.c resulting in a denial of service

High 7.5
2019-02-21< 7.1.25

php: Buffer over-read in PHAR reading functions

High 7.5
2019-02-22< 7.1.26

php: memcpy with negative length via crafted DNS response

High 7.5
2019-02-22< 7.1.26

php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c

High 7.5
2019-03-08< 7.1.27

php: File rename across filesystems may allow unwanted access during processing

High 7.5
2019-03-08< 7.1.27

php: Uninitialized read in exif_process_IFD_in_MAKERNOTE

High 7.5
2019-03-08< 7.1.27

php: Uninitialized read in exif_process_IFD_in_MAKERNOTE

High 7.5
2019-03-08< 7.1.27

php: Invalid read in exif_process_SOFn()

High 7.4
2017-03-27< 7.1.3

php: potential SSRF via fsockopen

High 7.1
2019-08-09< 7.1.31

heap-buffer-overflow on exif_process_user_comment in EXIF extension

High 7.1
2019-08-09< 7.1.31

heap-buffer-overflow on exif_scan_thumbnail in EXIF extension

Medium 6.5 Unfixed
2022-09-28≤ 7.1.33

$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

Medium 6.5
2018-02-19< 7.1.20

php: Infinite loop in php-fpm when restarting a child using program execution function

Medium 6.5
2017-08-02< 7.1.7

php: Buffer over-read from unitialized data in gdImageCreateFromGifCtx function

Medium 6.1
2018-04-29< 7.1.17

php: Reflected XSS vulnerability on PHAR 403 and 404 error pages

Medium 6.1
2018-09-16< 7.1.22

php: Cross-site scripting (XSS) flaw in Apache2 component via body of 'Transfer-Encoding: chunked' request

Medium 6.1
2018-01-16< 7.1.17

php: Reflected XSS on PHAR 404 page

Medium 5.5
2018-08-02< 7.1.20

php: exif: Buffer over-read in exif_process_IFD_in_MAKERNOTE()

Medium 5.5
2018-01-16< 7.1.13

gd: Infinite loop in gdImageCreateFromGifCtx() in gd_gif_in.c

Medium 5.3
2019-06-18< 7.1.30

Uninitialized read in gdImageCreateFromXbm

Medium 4.7
2018-04-29< 7.1.16

php: Dumpable FPM child processes allow bypassing opcache access controls

Low 2.3 Unfixed
2022-09-28≤ 7.1.33

phar wrapper can occur dos when using quine gzip file

N/A
2017-03-15< 7.1.1

N/A
2017-03-15< 7.1.1

N/A
2017-03-15< 7.1.26