OOB access in ldap_escape
PHP 8.1
Stream HTTP wrapper truncates redirect location to 1024 bytes
Integer overflow in the firebird and dblib quoters causing OOB writes
Argument Injection in PHP-CGI
XKCP: buffer overflow in the SHA-3 reference implementation
Command injection via array-ish $command parameter of proc_open()
Buffer overflow and overread in phar_dir_read()
PDO::quote() may return unquoted string
Security issue with external entity loading in XML without enabling it
UAF due to php_filter_float() failing
PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)
Freeing unallocated memory in php_pgsql_free_params()
Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)
Heap buffer overflow in finfo_buffer
password_verify() always returns true for some invalid hashes
NULL Pointer Dereference in PDO quoting
Information Leak of Memory in getimagesize
cgi.force_redirect configuration is bypassable due to the environment variable collision
php: Out of bounds access in php_pcre.c:php_pcre_replace_impl()
mysqlnd/pdo password buffer overflow
Array overrun in common path resolve code
DoS vulnerability when parsing multipart request body
Stream HTTP wrapper header check might omit basic auth header
Heap buffer overflow in array_merge()
PHP function password_verify can erroneously return true when argument contains NUL
OOB read due to insufficient input validation in imageloadfont()
$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities
NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix
pgsql extension does not check for errors during escaping
PHP is vulnerable to the Marvin Attack
Leak partial content of the heap through heap buffer over-read in mysqlnd
Streams HTTP wrapper does not fail for headers with invalid name and no colon
libxml streams use wrong content-type header when requesting a redirected resource
Filter bypass in filter_var (FILTER_VALIDATE_URL)
Configuring a proxy in a stream context might allow for CRLF injection in URIs
Single byte overread with convert.quoted-printable-decode filter
Null byte termination in hostnames
PHP-FPM logs from children may be altered
Header parser of http stream wrapper does not handle folded headers
Erroneous parsing of multipart form data
Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP
phar wrapper can occur dos when using quine gzip file