VYPR

zip extension

by PHP

CVEs (2)

  • CVE-2011-1470Mar 20, 2011
    risk 0.04cvss epss 0.10

    The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that is not properly handled by the stream_get_contents function.

  • CVE-2019-11036May 3, 2019
    risk 0.00cvss epss 0.07

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.