This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:php:php:5.3.22
Detail
VendorPhpFirst view 2012-05-21
ProductPhpLast view2019-03-08
Version5.3.22TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:php:php

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
 DateAlertAccess VectorAccess ComplexityAuthentication
7.52019-03-08CVE-2019-9641NetworkLowNone Requ...
52019-03-08CVE-2019-9639NetworkLowNone Requ...
52019-03-08CVE-2019-9638NetworkLowNone Requ...
52019-03-08CVE-2019-9637NetworkLowNone Requ...
52019-02-22CVE-2019-9024NetworkLowNone Requ...
Hide | Show 20 More...
 DateAlertAccess VectorAccess ComplexityAuthentication
7.52019-02-22CVE-2019-9023NetworkLowNone Requ...
7.52019-02-22CVE-2019-9021NetworkLowNone Requ...
7.52019-02-22CVE-2019-9020NetworkLowNone Requ...
52019-02-21CVE-2018-20783NetworkLowNone Requ...
6.82019-01-26CVE-2019-6977NetworkMediumNone Requ...
52018-12-07CVE-2018-19935NetworkLowNone Requ...
6.52018-11-25CVE-2018-19520NetworkLowRequires ...
52018-11-20CVE-2018-19396NetworkLowNone Requ...
52018-11-20CVE-2018-19395NetworkLowNone Requ...
4.32018-09-16CVE-2018-17082NetworkMediumNone Requ...
52018-08-07CVE-2018-15132NetworkLowNone Requ...
52018-08-03CVE-2018-14883NetworkLowNone Requ...
4.32018-08-02CVE-2018-14851NetworkMediumNone Requ...
6.82018-04-29CVE-2018-10549NetworkMediumNone Requ...
52018-04-29CVE-2018-10548NetworkLowNone Requ...
4.32018-04-29CVE-2018-10547NetworkMediumNone Requ...
52018-04-29CVE-2018-10546NetworkLowNone Requ...
1.92018-04-29CVE-2018-10545LocalMediumNone Requ...
7.52018-03-01CVE-2018-7584NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
27% (50)CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
13% (24)CWE-20Improper Input Validation
8% (15)CWE-125Out-of-bounds Read
7% (14)CWE-189Numeric Errors
5% (10)CWE-416Use After Free
Hide | Show 20 More...
%idName
4% (9)CWE-476NULL Pointer Dereference
4% (9)CWE-200Information Exposure
4% (9)CWE-190Integer Overflow or Wraparound
3% (6)CWE-787Out-of-bounds Write
2% (5)CWE-399Resource Management Errors
2% (4)CWE-264Permissions, Privileges, and Access Controls
2% (4)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
1% (3)CWE-400Uncontrolled Resource Consumption ('Resource Exhaustion')
1% (3)CWE-19Data Handling
1% (2)CWE-502Deserialization of Untrusted Data
1% (2)CWE-284Access Control (Authorization) Issues
1% (2)CWE-74Failure to Sanitize Data into a Different Plane ('Injection')
1% (2)CWE-59Improper Link Resolution Before File Access ('Link Following')
1% (2)CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path ...
0% (1)CWE-754Improper Check for Unusual or Exceptional Conditions
0% (1)CWE-415Double Free
0% (1)CWE-254Security Features
0% (1)CWE-94Failure to Control Generation of Code ('Code Injection')
0% (1)CWE-78Improper Sanitization of Special Elements used in an OS Command ('O...
0% (1)CWE-17Code

Oval Markup Language : Definitions

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalIDName
oval:org.mitre.oval:def:29107HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...
oval:org.mitre.oval:def:21035RHSA-2013:1050: php53 security update (Critical)
oval:org.mitre.oval:def:20931RHSA-2013:1049: php security update (Critical)
oval:org.mitre.oval:def:18965DSA-2723-1 php5 - heap corruption
oval:org.mitre.oval:def:24124ELSA-2013:1049: php security update (Critical)
Hide | Show 20 More...
idName
oval:org.mitre.oval:def:23414ELSA-2013:1050: php53 security update (Critical)
oval:org.mitre.oval:def:23370DEPRECATED: ELSA-2013:1049: php security update (Critical)
oval:org.mitre.oval:def:25866SUSE-SU-2013:1285-2 -- Security update for PHP5
oval:org.mitre.oval:def:25802SUSE-SU-2013:1317-1 -- Security update for PHP5
oval:org.mitre.oval:def:25747SUSE-SU-2013:1316-1 -- Security update for PHP5
oval:org.mitre.oval:def:25298SUSE-SU-2013:1285-1 -- Security update for PHP5
oval:org.mitre.oval:def:27533DEPRECATED: ELSA-2013-1050 -- php53 security update (critical)
oval:org.mitre.oval:def:27441DEPRECATED: ELSA-2013-1049 -- php security update (critical)
oval:org.mitre.oval:def:21114RHSA-2013:1307: php53 security, bug fix and enhancement update (Moderate)
oval:org.mitre.oval:def:18927USN-1937-1 -- php5 vulnerability
oval:org.mitre.oval:def:18760DSA-2742-1 php5 - interpretation conflict
oval:org.mitre.oval:def:23222ELSA-2013:1307: php53 security, bug fix and enhancement update (Moderate)
oval:org.mitre.oval:def:25611SUSE-SU-2014:0063-1 -- Security update for PHP5
oval:org.mitre.oval:def:25595SUSE-SU-2014:0064-1 -- Security update for PHP5
oval:org.mitre.oval:def:25081SUSE-SU-2014:0062-1 -- Security update for PHP5
oval:org.mitre.oval:def:26232SUSE-SU-2014:0873-1 -- Security update for PHP5
oval:org.mitre.oval:def:27044RHSA-2013:1615 -- php security, bug fix, and enhancement update (Moderate)
oval:org.mitre.oval:def:27442ELSA-2013-1615 -- php security, bug fix, and enhancement update (moderate)
oval:org.mitre.oval:def:27418DEPRECATED: ELSA-2013-1307 -- php53 security, bug fix and enhancement update ...
oval:org.mitre.oval:def:26428HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser...

ExploitDB Exploits

idDescription
30395PHP openssl_x509_parse() - Memory Corruption Vulnerability

OpenVAS Exploits

idDescription
2012-05-23Name : PHP 'com_print_typeinfo()' Remote Code Execution Vulnerability (Windows)
File : nvt/secpod_php_typeinfo_code_exec_vuln.nasl

Information Assurance Vulnerability Management (IAVM)

idDescription
2015-B-0108Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0061365
2015-A-0199Multiple Vulnerabilities in Apple Mac OS X
Severity : Category I - VMSKEY : V0061337
2014-B-0086Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0052897
2014-B-0021Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0044541
2014-A-0030Apple Mac OS X Security Update 2014-001
Severity : Category I - VMSKEY : V0044547
Hide | Show 2 More...
idDescription
2013-A-0179Apple Mac OS X Security Update 2013-004
Severity : Category I - VMSKEY : V0040373
2013-B-0093Multiple Vulnerabilities in PHP
Severity : Category I - VMSKEY : V0040108

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
DateDescription
2019-05-07PHP gdImageColorMatch heap buffer overflow file download attempt
RuleID : 49673 - Type : SERVER-OTHER - Revision : 1
2019-05-07PHP gdImageColorMatch heap buffer overflow file upload attempt
RuleID : 49672 - Type : SERVER-OTHER - Revision : 1
2018-12-11CVE PHP infinite loop from use of stream filter and convert.iconv file upload...
RuleID : 48354 - Type : SERVER-WEBAPP - Revision : 2
2018-06-26PHP .phar cross site scripting attempt
RuleID : 46808 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44749 - Type : SERVER-WEBAPP - Revision : 2
Hide | Show 20 More...
DateDescription
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44748 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44747 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44746 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44745 - Type : SERVER-WEBAPP - Revision : 2
2017-12-13PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a...
RuleID : 44744 - Type : SERVER-WEBAPP - Revision : 2
2017-10-24PHP form-based file upload DoS attempt
RuleID : 44390 - Type : SERVER-WEBAPP - Revision : 2
2017-09-19PHP malformed quoted printable denial of service attempt
RuleID : 44001 - Type : SERVER-WEBAPP - Revision : 2
2017-08-23PHP core unserialize use after free attempt
RuleID : 43668 - Type : SERVER-WEBAPP - Revision : 2
2017-07-18Oniguruma expression parser out of bounds write attempt
RuleID : 43182 - Type : FILE-OTHER - Revision : 2
2017-07-18Oniguruma expression parser out of bounds write attempt
RuleID : 43181 - Type : FILE-OTHER - Revision : 2
2017-03-28PHP Exception Handling remote denial of service attempt
RuleID : 41690 - Type : SERVER-OTHER - Revision : 2
2017-03-28PHP Exception Handling remote denial of service attempt
RuleID : 41689 - Type : SERVER-OTHER - Revision : 2
2017-02-23PHP ZipArchive getFromIndex and getFromName integer overflow attempt
RuleID : 41384 - Type : SERVER-WEBAPP - Revision : 2
2017-02-23PHP ZipArchive getFromIndex and getFromName integer overflow attempt
RuleID : 41383 - Type : SERVER-WEBAPP - Revision : 2
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40297 - Type : FILE-IMAGE - Revision : 3
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40296 - Type : FILE-IMAGE - Revision : 2
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40295 - Type : FILE-IMAGE - Revision : 2
2016-11-01PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt
RuleID : 40294 - Type : FILE-IMAGE - Revision : 2
2016-10-20PHP exif_process_user_comment null pointer dereference attempt
RuleID : 40248 - Type : FILE-IMAGE - Revision : 3
2016-10-20PHP exif_process_user_comment null pointer dereference attempt
RuleID : 40247 - Type : FILE-IMAGE - Revision : 2

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
idDescription
2019-01-14Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2019-1147.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-ee6707d519.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-b6072889db.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-1aeac808ce.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-791c3cfe21.nasl - Type : ACT_GATHER_INFO
Hide | Show 20 More...
idDescription
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-7ebfe1e6f2.nasl - Type : ACT_GATHER_INFO
2019-01-03Name : The remote Fedora host is missing a security update.
File : fedora_2018-dfe1f0bac6.nasl - Type : ACT_GATHER_INFO
2018-12-17Name : The remote Debian host is missing a security update.
File : debian_DLA-1608.nasl - Type : ACT_GATHER_INFO
2018-12-11Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4353.nasl - Type : ACT_GATHER_INFO
2018-12-03Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201812-01.nasl - Type : ACT_GATHER_INFO
2018-10-26Name : The remote EulerOS Virtualization host is missing a security update.
File : EulerOS_SA-2018-1325.nasl - Type : ACT_GATHER_INFO
2018-10-19Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1090.nasl - Type : ACT_GATHER_INFO
2018-09-27Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1309.nasl - Type : ACT_GATHER_INFO
2018-09-27Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1310.nasl - Type : ACT_GATHER_INFO
2018-09-24Name : The remote Fedora host is missing a security update.
File : fedora_2018-25100b492c.nasl - Type : ACT_GATHER_INFO
2018-09-20Name : The remote Debian host is missing a security update.
File : debian_DLA-1509.nasl - Type : ACT_GATHER_INFO
2018-09-18Name : The remote EulerOS Virtualization host is missing a security update.
File : EulerOS_SA-2018-1249.nasl - Type : ACT_GATHER_INFO
2018-09-04Name : The remote Debian host is missing a security update.
File : debian_DLA-1490.nasl - Type : ACT_GATHER_INFO
2018-08-24Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1066.nasl - Type : ACT_GATHER_INFO
2018-08-24Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2018-1067.nasl - Type : ACT_GATHER_INFO
2018-08-17Name : The remote PhotonOS host is missing multiple security updates.
File : PhotonOS_PHSA-2017-0021.nasl - Type : ACT_GATHER_INFO
2018-08-17Name : The remote PhotonOS host is missing multiple security updates.
File : PhotonOS_PHSA-2017-0029.nasl - Type : ACT_GATHER_INFO
2018-08-10Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1224.nasl - Type : ACT_GATHER_INFO
2018-07-06Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4240.nasl - Type : ACT_GATHER_INFO
2018-07-03Name : The remote EulerOS host is missing a security update.
File : EulerOS_SA-2018-1217.nasl - Type : ACT_GATHER_INFO