Search CVE reports


Toggle filters

321 – 330 of 656 results


CVE-2015-1352

Medium priority
Fixed

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2015-1351

Medium priority
Fixed

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2014-9621

Low priority

Some fixes available 1 of 5

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

2 affected packages

php5, file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5 Not in release Not in release
file Not affected Not affected
Show less packages

CVE-2014-9620

Low priority

Some fixes available 1 of 5

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

2 affected packages

file, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file Not affected Not affected
php5 Not in release Not in release
Show less packages

CVE-2014-9652

Low priority
Fixed

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of...

2 affected packages

file, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
file
php5
Show less packages

CVE-2014-9427

Low priority
Fixed

sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2014-9426

Medium priority
Not affected

The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service...

2 affected packages

php5, file

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
file
Show less packages

CVE-2014-9425

Medium priority
Not affected

Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2014-9767

Low priority

Some fixes available 3 of 4

Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers...

3 affected packages

hhvm, php5, php7.0

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hhvm Not in release Not in release Not in release Not affected
php5 Not in release Not in release Not in release Not in release
php7.0 Not in release Not in release Not in release Not in release
Show less packages

CVE-2014-9705

Medium priority
Fixed

Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages