VYPR

rpm package

suse/php5&distro=SUSE Linux Enterprise Software Development Kit 12 SP4

pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4

Vulnerabilities (33)

  • CVE-2019-9641Mar 8, 2019
    affected < 5.5.14-109.51.6fixed 5.5.14-109.51.6

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

  • CVE-2019-9640Mar 8, 2019
    affected < 5.5.14-109.58.1fixed 5.5.14-109.58.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.

  • CVE-2019-9639Mar 8, 2019
    affected < 5.5.14-109.58.1fixed 5.5.14-109.58.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.

  • CVE-2019-9638Mar 8, 2019
    affected < 5.5.14-109.58.1fixed 5.5.14-109.58.1

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note->offset relationship to value_len.

  • CVE-2019-9637Mar 8, 2019
    affected < 5.5.14-109.58.1fixed 5.5.14-109.58.1

    An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unau

  • CVE-2019-9024Feb 22, 2019
    affected < 5.5.14-109.51.6fixed 5.5.14-109.51.6

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.

  • CVE-2019-9023Feb 22, 2019
    affected < 5.5.14-109.51.6fixed 5.5.14-109.51.6

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstr

  • CVE-2019-9021Feb 22, 2019
    affected < 5.5.14-109.51.6fixed 5.5.14-109.51.6

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when tryi

  • CVE-2019-9020Feb 22, 2019
    affected < 5.5.14-109.51.6fixed 5.5.14-109.51.6

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in

  • CVE-2018-20783Feb 21, 2019
    affected < 5.5.14-109.51.6fixed 5.5.14-109.51.6

    In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_

  • CVE-2019-6977Jan 27, 2019
    affected < 5.5.14-109.48.1fixed 5.5.14-109.48.1

    gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker

  • CVE-2018-19518Nov 25, 2018
    affected < 5.5.14-109.45.2fixed 5.5.14-109.45.2

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, wh

  • CVE-2015-1351Mar 30, 2015
    affected < 5.5.14-109.63.2fixed 5.5.14-109.63.2

    Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Page 2 of 2