CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
OOB read / info leak in convert.* stream filters when line-break-chars contains NUL
IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)
TLS Hostname Verification Falls Back to CN After SAN Mismatch
Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN
Various packet overreads in mysqlnd_writeprotocol.c
Cross-origin credential leak in HTTP stream wrapper redirects
SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
Integer overflow to buffer overflow in soap HTTP parsing
PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS
Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection
Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header
Stack overflow in phar with circular symlinks
Out-of-bounds write in bccomp() via crafted operand and scale
SQL injection in ext-pgsql via E'...' backslash breakout
ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
DoS attack via DOMNode::C14N()
Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding
Out-of-bounds read in urldecode() on NetBSD
Use-After-Free in SOAP using Apache map
Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
SoapServer session-persisted object use-after-free via SOAP header fault
NULL pointer dereference in SOAP apache:Map decoder with missing <value>
SQL injection in pdo_firebird via NUL bytes in quoted strings
Signed integer overflow in metaphone()
Showing 1 to 25 CVEs · page 1 (more available)