This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:php:php:5.4.25:-
Detail
VendorPhpFirst view 2012-05-21
ProductPhpLast view2019-03-08
Version5.4.25TypeApplication
Edition 
Language 
Update- 
 
CPE Productcpe:/a:php:php

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
 DateAlertAccess VectorAccess ComplexityAuthentication
7.52019-03-08CVE-2019-9641NetworkLowNone Requ...
52019-03-08CVE-2019-9639NetworkLowNone Requ...
52019-03-08CVE-2019-9638NetworkLowNone Requ...
52019-03-08CVE-2019-9637NetworkLowNone Requ...
52019-02-22CVE-2019-9024NetworkLowNone Requ...
Hide | Show 20 More...
 DateAlertAccess VectorAccess ComplexityAuthentication
7.52019-02-22CVE-2019-9023NetworkLowNone Requ...
7.52019-02-22CVE-2019-9021NetworkLowNone Requ...
7.52019-02-22CVE-2019-9020NetworkLowNone Requ...
6.82019-01-26CVE-2019-6977NetworkMediumNone Requ...
52018-12-07CVE-2018-19935NetworkLowNone Requ...
4.32018-09-16CVE-2018-17082NetworkMediumNone Requ...
52018-08-03CVE-2018-14883NetworkLowNone Requ...
4.32018-08-02CVE-2018-14851NetworkMediumNone Requ...
6.82018-04-29CVE-2018-10549NetworkMediumNone Requ...
52018-04-29CVE-2018-10548NetworkLowNone Requ...
4.32018-04-29CVE-2018-10547NetworkMediumNone Requ...
52018-04-29CVE-2018-10546NetworkLowNone Requ...
1.92018-04-29CVE-2018-10545LocalMediumNone Requ...
7.52018-03-01CVE-2018-7584NetworkLowNone Requ...
6.82018-02-19CVE-2015-9253NetworkLowRequires ...
52018-02-09CVE-2016-10712NetworkLowNone Requ...
4.32018-01-16CVE-2018-5712NetworkMediumNone Requ...
4.32018-01-16CVE-2018-5711NetworkMediumNone Requ...
52017-11-07CVE-2017-16642NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
27% (48)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
13% (23)CWE-20Improper Input Validation
8% (14)CWE-125Out-of-bounds Read
7% (13)CWE-189Numeric Errors
5% (10)CWE-416Use After Free
Hide | Show 20 More...
%idName
5% (9)CWE-190Integer Overflow or Wraparound
4% (8)CWE-476NULL Pointer Dereference
4% (7)CWE-200Information Exposure
3% (6)CWE-787Out-of-bounds Write
2% (5)CWE-399Resource Management Errors
2% (4)CWE-400Uncontrolled Resource Consumption ('Resource Exhaustion')
2% (4)CWE-264Permissions, Privileges, and Access Controls
2% (4)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
1% (3)CWE-19Data Handling
1% (2)CWE-502Deserialization of Untrusted Data
1% (2)CWE-284Access Control (Authorization) Issues
1% (2)CWE-74Failure to Sanitize Data into a Different Plane ('Injection')
1% (2)CWE-59Improper Link Resolution Before File Access ('Link Following')
1% (2)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
0% (1)CWE-754Improper Check for Unusual or Exceptional Conditions
0% (1)CWE-415Double Free
0% (1)CWE-310Cryptographic Issues
0% (1)CWE-254Security Features
0% (1)CWE-78Improper Sanitization of Special Elements used in an OS Command ('O...
0% (1)CWE-17Code

Oval Markup Language : Definitions

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalIDName
oval:org.mitre.oval:def:29107HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:29013HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:26455DSA-3021-1 file - security update
oval:org.mitre.oval:def:27096USN-2369-1 -- file vulnerability
oval:org.mitre.oval:def:27986DSA-3021-2 -- file regression update
Hide | Show 20 More...
idName
oval:org.mitre.oval:def:24369USN-2126-1 -- php5 vulnerabilities
oval:org.mitre.oval:def:28064DSA-3008-2 -- php5 regression update
oval:org.mitre.oval:def:28245SUSE-SU-2014:1441-1 -- Security update for php53 (moderate)
oval:org.mitre.oval:def:29112HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:27101RHSA-2014:1606: file security and bug fix update (Moderate)
oval:org.mitre.oval:def:26966HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:29216HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:29040HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:27209RHSA-2014:1327: php security update (Moderate)
oval:org.mitre.oval:def:27173ELSA-2014-1327 -- php security update (moderate)
oval:org.mitre.oval:def:26896SUSE-SU-2014:1141-1 -- Security update for php53
oval:org.mitre.oval:def:26755USN-2344-1 -- php5 vulnerabilities
oval:org.mitre.oval:def:25226USN-2276-1 -- php5 vulnerabilities
oval:org.mitre.oval:def:24837DSA-2974-1 -- php5 - security update
oval:org.mitre.oval:def:25721SUSE-SU-2014:0938-1 -- Security update for PHP 5.3
oval:org.mitre.oval:def:26421RHSA-2014:1013: php security update (Moderate)
oval:org.mitre.oval:def:26314RHSA-2014:1012: php53 and php security update (Moderate)
oval:org.mitre.oval:def:26721ELSA-2014-1013 -- php security update (moderate)
oval:org.mitre.oval:def:27171RHSA-2014:1326: php53 and php security update (Moderate)
oval:org.mitre.oval:def:27280ELSA-2014-1326 -- php53 and php security update (moderate)

OpenVAS Exploits

idDescription
2012-05-23Name : PHP 'com_print_typeinfo()' Remote Code Execution Vulnerability (Windows)
File : nvt/secpod_php_typeinfo_code_exec_vuln.nasl

Information Assurance Vulnerability Management (IAVM)

idDescription
2015-B-0108Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0061365
2015-A-0199Multiple Vulnerabilities in Apple Mac OS X
Severity : Category I - VMSKEY : V0061337
2014-B-0086Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0052897
2014-B-0021Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0044541
2013-B-0093Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0040108

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
DateDescription
2019-05-07PHP gdImageColorMatch heap buffer overflow file download attempt
RuleID : 49673 - Type : SERVER-OTHER - Revision : 1
2019-05-07PHP gdImageColorMatch heap buffer overflow file upload attempt
RuleID : 49672 - Type : SERVER-OTHER - Revision : 1
2018-12-11CVE PHP infinite loop from use of stream filter and convert.iconv file upload...
RuleID : 48354 - Type : SERVER-WEBAPP - Revision : 2
2018-06-26PHP .phar cross site scripting attempt
RuleID : 46808 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44749 - Type : SERVER-WEBAPP - Revision : 2
Hide | Show 20 More...
DateDescription
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44748 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44747 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44746 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44745 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44744 - Type : SERVER-WEBAPP - Revision : 2
2017-10-24PHP form-based file upload DoS attempt
RuleID : 44390 - Type : SERVER-WEBAPP - Revision : 2
2017-08-23PHP core unserialize use after free attempt
RuleID : 43668 - Type : SERVER-WEBAPP - Revision : 2
2017-07-18Oniguruma expression parser out of bounds write attempt
RuleID : 43182 - Type : FILE-OTHER - Revision : 2
2017-07-18Oniguruma expression parser out of bounds write attempt
RuleID : 43181 - Type : FILE-OTHER - Revision : 2
2017-03-28PHP Exception Handling remote denial of service attempt
RuleID : 41690 - Type : SERVER-OTHER - Revision : 2
2017-03-28PHP Exception Handling remote denial of service attempt
RuleID : 41689 - Type : SERVER-OTHER - Revision : 2
2017-02-23PHP ZipArchive getFromIndex and getFromName integer overflow attempt
RuleID : 41384 - Type : SERVER-WEBAPP - Revision : 2
2017-02-23PHP ZipArchive getFromIndex and getFromName integer overflow attempt
RuleID : 41383 - Type : SERVER-WEBAPP - Revision : 2
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40297 - Type : FILE-IMAGE - Revision : 3
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40296 - Type : FILE-IMAGE - Revision : 2
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40295 - Type : FILE-IMAGE - Revision : 2
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40294 - Type : FILE-IMAGE - Revision : 2
2016-10-20PHP exif_process_user_comment null pointer dereference attempt
RuleID : 40248 - Type : FILE-IMAGE - Revision : 3
2016-10-20PHP exif_process_user_comment null pointer dereference attempt
RuleID : 40247 - Type : FILE-IMAGE - Revision : 2
2016-10-20PHP exif_process_user_comment null pointer dereference attempt
RuleID : 40246 - Type : FILE-IMAGE - Revision : 3

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
idDescription
2019-01-14Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2019-1147.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-ee6707d519.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-b6072889db.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-1aeac808ce.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-791c3cfe21.nasl - Type : ACT_GATHER_INFO
Hide | Show 20 More...
idDescription
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-7ebfe1e6f2.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-dfe1f0bac6.nasl - Type : ACT_GATHER_INFO
2018-12-17Name : The remote Debian host is missing a security update.
File : debian_DLA-1608.nasl - Type : ACT_GATHER_INFO
2018-12-11Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4353.nasl - Type : ACT_GATHER_INFO
2018-12-03Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201812-01.nasl - Type : ACT_GATHER_INFO
2018-10-26Name : The remote EulerOS Virtualization host is missing a security update.
File : EulerOS_SA-2018-1325.nasl - Type : ACT_GATHER_INFO
2018-10-19Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1090.nasl - Type : ACT_GATHER_INFO
2018-09-27Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1309.nasl - Type : ACT_GATHER_INFO
2018-09-27Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1310.nasl - Type : ACT_GATHER_INFO
2018-09-24Name : The remote Fedora host is missing a security update.
File : fedora_2018-25100b492c.nasl - Type : ACT_GATHER_INFO
2018-09-20Name : The remote Debian host is missing a security update.
File : debian_DLA-1509.nasl - Type : ACT_GATHER_INFO
2018-09-18Name : The remote EulerOS Virtualization host is missing a security update.
File : EulerOS_SA-2018-1249.nasl - Type : ACT_GATHER_INFO
2018-09-04Name : The remote Debian host is missing a security update.
File : debian_DLA-1490.nasl - Type : ACT_GATHER_INFO
2018-08-24Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1066.nasl - Type : ACT_GATHER_INFO
2018-08-24Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1067.nasl - Type : ACT_GATHER_INFO
2018-08-17Name : The remote PhotonOS host is missing multiple security updates.
File : PhotonOS_PHSA-2017-0021.nasl - Type : ACT_GATHER_INFO
2018-08-17Name : The remote PhotonOS host is missing multiple security updates.
File : PhotonOS_PHSA-2017-0029.nasl - Type : ACT_GATHER_INFO
2018-08-10Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1224.nasl - Type : ACT_GATHER_INFO
2018-07-06Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4240.nasl - Type : ACT_GATHER_INFO
2018-07-03Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1217.nasl - Type : ACT_GATHER_INFO