Argument Injection in PHP-CGI
PHP 7.4
php: Overflowing the length of string causes crash
php: Integer overflow in mysqli_api.c:mysqli_real_escape_string()
XKCP: buffer overflow in the SHA-3 reference implementation
UAF due to php_filter_float() failing
Freeing unallocated memory in php_pgsql_free_params()
PHP-FPM memory access in root process leading to privilege escalation
php: Out of bounds access in php_pcre.c:php_pcre_replace_impl()
Null Pointer Dereference in PHP Session Upload Progress
OOB Read in urldecode()
mysqlnd/pdo password buffer overflow
mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full
heap-buffer-overflow on exif_scan_thumbnail in EXIF extension
heap-buffer-overflow on exif_process_user_comment in EXIF extension
mail() may release string with refcount==1 twice
OOB read in php_strip_tags_ex
global buffer-overflow in mbfl_filt_conv_big5_wchar
heap-buffer-overflow in phar_extract_file
Use-of-uninitialized-value in exif
$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities
OOB read due to insufficient input validation in imageloadfont()
Files added to tar with Phar::buildFromIterator have all-access permissions
Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV
Filter bypass in filter_var (FILTER_VALIDATE_URL)
Temporary files are not cleaned after OOM when parsing HTTP request data
get_headers() silently truncates after a null byte
FILTER_VALIDATE_URL accepts URLs with invalid userinfo
Null Dereference in SoapClient
ZipArchive::extractTo may extract outside of destination dir
Special characters break path parsing in XML functions
Multiple vulnerabilities in Firebird client extension
Heap-buffer-overflow READ in exif
Use-after-free in exif parsing under memory sanitizer
Use of freed hash key in the phar_parse_zipfile function
PHP parses encoded cookie names so malicious `__Host-` cookies can be sent
Incorrect URL validation in FILTER_VALIDATE_URL
link() silently truncates after a null byte on Windows
DirectoryIterator class silently truncates after a null byte
Buffer underflow in bc_shift_addsub
phar wrapper can occur dos when using quine gzip file