PHP 7.3

Status EOLSupport 2018-12 – 2021-12Latest 7.3.33Vulnerabilities 60← All PHP versions
KEV Unfixed
2024-06-09≤ 7.3.33

Argument Injection in PHP-CGI

Critical 9.8 Unfixed
2017-05-12≤ 7.3.33

php: Overflowing the length of string causes crash

Critical 9.8
2019-07-10< 7.3.9

oniguruma: Use-after-free in onig_new_deluxe() in regext.c

Critical 9.8
2019-02-22< 7.3.1

php: Invalid memory access in function xmlrpc_decode()

Critical 9.8
2019-02-22< 7.3.1

php: Heap-based buffer over-read in PHAR reading functions

Critical 9.8
2019-02-22< 7.3.1

php: Heap-based buffer over-read in mbstring regular expression functions

Critical 9.8
2019-02-22< 7.3.1

php: Negative size parameter in mb_split

Critical 9.8
2019-03-08< 7.3.3

php: Uninitialized read in exif_process_IFD_in_TIFF

Critical 9.1
2019-04-18< 7.3.4

Heap over-read in PHP EXIF extension

Critical 9.1
2019-04-18< 7.3.4

Heap over-read in PHP EXIF extension

Critical 9.1
2019-05-03< 7.3.5

Heap over-read in PHP EXIF extension

Critical 9.1
2019-06-18< 7.3.6

Out-of-bounds read in iconv.c

Critical 9.1
2019-06-18< 7.3.6

Heap buffer overflow in EXIF extension

High 8.8
2019-01-27< 7.3.1

gd: Heap-based buffer overflow in gdImageColorMatch() in gd_color_match.c

KEV
2019-10-28< 7.3.11

Underflow in PHP-FPM can lead to RCE

High 8.1
2019-03-11< 7.3.3

php: buffer overflow in ext/phar/tar.c

High 7.8
2021-10-25< 7.3.32

PHP-FPM memory access in root process leading to privilege escalation

High 7.5
2019-11-25< 7.3.10

oniguruma: Heap-based buffer overflow in str_lower_case_match in regexec.c

High 7.5
2019-02-21< 7.3.0

php: Buffer over-read in PHAR reading functions

High 7.5
2018-11-25< 7.3.0

php: imap_open() allows running arbitrary shell commands via mailbox parameter

High 7.5
2018-12-07< 7.3.0

php: NULL pointer dereference in ext/imap/php_imap.c resulting in a denial of service

High 7.5
2019-02-22< 7.3.2

php: memcpy with negative length via crafted DNS response

High 7.5
2019-02-22< 7.3.1

php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c

High 7.5
2019-03-08< 7.3.3

php: File rename across filesystems may allow unwanted access during processing

High 7.5
2019-03-08< 7.3.3

php: Uninitialized read in exif_process_IFD_in_MAKERNOTE

High 7.5
2019-03-08< 7.3.3

php: Uninitialized read in exif_process_IFD_in_MAKERNOTE

High 7.5
2019-03-08< 7.3.3

php: Invalid read in exif_process_SOFn()

High 7.5
2020-02-27< 7.3.15

Null Pointer Dereference in PHP Session Upload Progress

High 7.5
2020-04-27< 7.3.17

OOB Read in urldecode()

High 7.4
2020-04-01< 7.3.16

mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full

High 7.1
2019-08-09< 7.3.8

heap-buffer-overflow on exif_process_user_comment in EXIF extension

High 7.1
2019-08-09< 7.3.8

heap-buffer-overflow on exif_scan_thumbnail in EXIF extension

Medium 6.5 Unfixed
2022-09-28≤ 7.3.33

$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

Medium 6.5
2018-02-19< 7.3.0

php: Infinite loop in php-fpm when restarting a child using program execution function

Medium 6.5
2019-12-23< 7.3.14

mail() may release string with refcount==1 twice

Medium 6.5
2020-02-10< 7.3.14

OOB read in php_strip_tags_ex

Medium 6.5
2020-02-10< 7.3.14

global buffer-overflow in mbfl_filt_conv_big5_wchar

Medium 6.5
2020-02-27< 7.3.15

heap-buffer-overflow in phar_extract_file

Medium 6.5
2020-04-01< 7.3.16

Use-of-uninitialized-value in exif

Medium 5.5
2020-02-27< 7.3.15

Files added to tar with Phar::buildFromIterator have all-access permissions

Medium 5.4
2020-10-02< 7.3.23

Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV

Medium 5.3 Unfixed
2024-06-09≥ 7.3.27 and ≤ 7.3.33

Filter bypass in filter_var (FILTER_VALIDATE_URL)

Medium 5.3
2019-06-18< 7.3.6

Uninitialized read in gdImageCreateFromXbm

Medium 5.3
2020-05-20< 7.3.18

Temporary files are not cleaned after OOM when parsing HTTP request data

Medium 5.3
2020-04-01< 7.3.16

get_headers() silently truncates after a null byte

Medium 5.3
2021-02-15< 7.3.26

FILTER_VALIDATE_URL accepts URLs with invalid userinfo

Medium 5.3
2021-02-15< 7.3.27

Null Dereference in SoapClient

Medium 5.3
2021-10-04< 7.3.31

ZipArchive::extractTo may extract outside of destination dir

Medium 5.3
2021-11-29< 7.3.33

Special characters break path parsing in XML functions

Medium 5.0
2021-10-04< 7.3.29

Multiple vulnerabilities in Firebird client extension

Medium 4.8
2019-12-23< 7.3.13

Heap-buffer-overflow READ in exif

Medium 4.8
2019-12-23< 7.3.13

Use-after-free in exif parsing under memory sanitizer

Medium 4.8
2020-09-09< 7.3.21

Use of freed hash key in the phar_parse_zipfile function

Medium 4.3
2020-10-02< 7.3.23

PHP parses encoded cookie names so malicious `__Host-` cookies can be sent

Medium 4.3
2021-10-04< 7.3.29

Incorrect URL validation in FILTER_VALIDATE_URL

Low 3.7
2019-12-23< 7.3.13

link() silently truncates after a null byte on Windows

Low 3.7
2019-12-23< 7.3.13

DirectoryIterator class silently truncates after a null byte

Low 3.7
2019-12-23< 7.3.13

Buffer underflow in bc_shift_addsub

Low 2.3 Unfixed
2022-09-28≤ 7.3.33

phar wrapper can occur dos when using quine gzip file

N/A
2017-03-15< 7.3.1