This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
Summuary | |
---|---|
CPE Name | cpe:/a:php:php:5.5.0:rc2 |
Detail | |||
---|---|---|---|
Vendor | Php | First view | 2013-08-13 |
Product | Php | Last view | 2019-03-08 |
Version | 5.5.0 | Type | Application |
Edition | |||
Language | |||
Update | rc2 | ||
CPE Product | cpe:/a:php:php |
Activity : Overall
Related : CVE
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
7.5 | 2019-03-08 | CVE-2019-9641 | Network | Low | None Requ... | |
5 | 2019-03-08 | CVE-2019-9639 | Network | Low | None Requ... | |
5 | 2019-03-08 | CVE-2019-9638 | Network | Low | None Requ... | |
5 | 2019-03-08 | CVE-2019-9637 | Network | Low | None Requ... | |
5 | 2019-02-22 | CVE-2019-9024 | Network | Low | None Requ... | |
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
7.5 | 2019-02-22 | CVE-2019-9023 | Network | Low | None Requ... | |
7.5 | 2019-02-22 | CVE-2019-9021 | Network | Low | None Requ... | |
7.5 | 2019-02-22 | CVE-2019-9020 | Network | Low | None Requ... | |
5 | 2019-02-21 | CVE-2018-20783 | Network | Low | None Requ... | |
6.8 | 2019-01-26 | CVE-2019-6977 | Network | Medium | None Requ... | |
5 | 2018-12-07 | CVE-2018-19935 | Network | Low | None Requ... | |
6.5 | 2018-11-25 | CVE-2018-19520 | Network | Low | Requires ... | |
5 | 2018-11-20 | CVE-2018-19396 | Network | Low | None Requ... | |
5 | 2018-11-20 | CVE-2018-19395 | Network | Low | None Requ... | |
4.3 | 2018-09-16 | CVE-2018-17082 | Network | Medium | None Requ... | |
5 | 2018-08-07 | CVE-2018-15132 | Network | Low | None Requ... | |
5 | 2018-08-03 | CVE-2018-14883 | Network | Low | None Requ... | |
4.3 | 2018-08-02 | CVE-2018-14851 | Network | Medium | None Requ... | |
6.8 | 2018-04-29 | CVE-2018-10549 | Network | Medium | None Requ... | |
5 | 2018-04-29 | CVE-2018-10548 | Network | Low | None Requ... | |
4.3 | 2018-04-29 | CVE-2018-10547 | Network | Medium | None Requ... | |
5 | 2018-04-29 | CVE-2018-10546 | Network | Low | None Requ... | |
1.9 | 2018-04-29 | CVE-2018-10545 | Local | Medium | None Requ... | |
7.5 | 2018-03-01 | CVE-2018-7584 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
% | id | Name |
---|---|---|
27% (50) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
11% (20) | CWE-20 | Improper Input Validation |
9% (17) | CWE-125 | Out-of-bounds Read |
8% (15) | CWE-189 | Numeric Errors |
5% (10) | CWE-416 | Use After Free |
% | id | Name |
---|---|---|
5% (9) | CWE-476 | NULL Pointer Dereference |
5% (9) | CWE-190 | Integer Overflow or Wraparound |
4% (8) | CWE-200 | Information Exposure |
3% (6) | CWE-787 | Out-of-bounds Write |
2% (5) | CWE-264 | Permissions, Privileges, and Access Controls |
2% (4) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
2% (4) | CWE-19 | Data Handling |
1% (3) | CWE-502 | Deserialization of Untrusted Data |
1% (3) | CWE-399 | Resource Management Errors |
1% (2) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
1% (2) | CWE-284 | Access Control (Authorization) Issues |
1% (2) | CWE-74 | Failure to Sanitize Data into a Different Plane ('Injection') |
1% (2) | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
0% (1) | CWE-770 | Allocation of Resources Without Limits or Throttling |
0% (1) | CWE-754 | Improper Check for Unusual or Exceptional Conditions |
0% (1) | CWE-681 | Incorrect Conversion between Numeric Types |
0% (1) | CWE-415 | Double Free |
0% (1) | CWE-362 | Race Condition |
0% (1) | CWE-310 | Cryptographic Issues |
0% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
Oval Markup Language : Definitions
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
OvalID | Name |
---|---|
oval:org.mitre.oval:def:29107 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:29013 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:28496 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:26455 | DSA-3021-1 file - security update |
oval:org.mitre.oval:def:27096 | USN-2369-1 -- file vulnerability |
id | Name |
---|---|
oval:org.mitre.oval:def:27986 | DSA-3021-2 -- file regression update |
oval:org.mitre.oval:def:24369 | USN-2126-1 -- php5 vulnerabilities |
oval:org.mitre.oval:def:29027 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:28921 | SUSE-SU-2015:0866-1 -- Security update for gd (low) |
oval:org.mitre.oval:def:28064 | DSA-3008-2 -- php5 regression update |
oval:org.mitre.oval:def:28245 | SUSE-SU-2014:1441-1 -- Security update for php53 (moderate) |
oval:org.mitre.oval:def:29112 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:27101 | RHSA-2014:1606: file security and bug fix update (Moderate) |
oval:org.mitre.oval:def:26966 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:29216 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:29040 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:27209 | RHSA-2014:1327: php security update (Moderate) |
oval:org.mitre.oval:def:27173 | ELSA-2014-1327 -- php security update (moderate) |
oval:org.mitre.oval:def:26896 | SUSE-SU-2014:1141-1 -- Security update for php53 |
oval:org.mitre.oval:def:26755 | USN-2344-1 -- php5 vulnerabilities |
oval:org.mitre.oval:def:25226 | USN-2276-1 -- php5 vulnerabilities |
oval:org.mitre.oval:def:24837 | DSA-2974-1 -- php5 - security update |
oval:org.mitre.oval:def:25721 | SUSE-SU-2014:0938-1 -- Security update for PHP 5.3 |
oval:org.mitre.oval:def:26421 | RHSA-2014:1013: php security update (Moderate) |
oval:org.mitre.oval:def:26314 | RHSA-2014:1012: php53 and php security update (Moderate) |
ExploitDB Exploits
id | Description |
---|---|
30395 | PHP openssl_x509_parse() - Memory Corruption Vulnerability |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2015-B-0108 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0061365 |
2015-A-0199 | Multiple Vulnerabilities in Apple Mac OS X Severity : Category I - VMSKEY : V0061337 |
2014-B-0086 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0052897 |
2014-B-0053 | PHP Privilege Escalation Vulnerability Severity : Category I - VMSKEY : V0050233 |
2014-B-0021 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0044541 |
id | Description |
---|---|
2014-A-0030 | Apple Mac OS X Security Update 2014-001 Severity : Category I - VMSKEY : V0044547 |
2013-B-0093 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0040108 |
Snort® IPS/IDS
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date | Description |
---|---|
2019-10-23 | PHP http fopen stack buffer overflow attempt RuleID : 51578 - Type : SERVER-WEBAPP - Revision : 1 |
2019-05-07 | PHP gdImageColorMatch heap buffer overflow file download attempt RuleID : 49673 - Type : SERVER-OTHER - Revision : 1 |
2019-05-07 | PHP gdImageColorMatch heap buffer overflow file upload attempt RuleID : 49672 - Type : SERVER-OTHER - Revision : 1 |
2018-12-11 | CVE PHP infinite loop from use of stream filter and convert.iconv file upload... RuleID : 48354 - Type : SERVER-WEBAPP - Revision : 2 |
2018-08-16 | PHP phar extension remote code execution attempt RuleID : 47207 - Type : SERVER-WEBAPP - Revision : 2 |
Date | Description |
---|---|
2018-06-26 | PHP .phar cross site scripting attempt RuleID : 46808 - Type : SERVER-WEBAPP - Revision : 2 |
2017-12-13 | PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a... RuleID : 44749 - Type : SERVER-WEBAPP - Revision : 2 |
2017-12-13 | PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a... RuleID : 44748 - Type : SERVER-WEBAPP - Revision : 2 |
2017-12-13 | PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a... RuleID : 44747 - Type : SERVER-WEBAPP - Revision : 2 |
2017-12-13 | PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a... RuleID : 44746 - Type : SERVER-WEBAPP - Revision : 2 |
2017-12-13 | PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a... RuleID : 44745 - Type : SERVER-WEBAPP - Revision : 2 |
2017-12-13 | PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption a... RuleID : 44744 - Type : SERVER-WEBAPP - Revision : 2 |
2017-10-24 | PHP form-based file upload DoS attempt RuleID : 44390 - Type : SERVER-WEBAPP - Revision : 2 |
2017-08-23 | PHP core unserialize use after free attempt RuleID : 43668 - Type : SERVER-WEBAPP - Revision : 2 |
2017-07-18 | Oniguruma expression parser out of bounds write attempt RuleID : 43182 - Type : FILE-OTHER - Revision : 2 |
2017-07-18 | Oniguruma expression parser out of bounds write attempt RuleID : 43181 - Type : FILE-OTHER - Revision : 2 |
2017-03-28 | PHP Exception Handling remote denial of service attempt RuleID : 41690 - Type : SERVER-OTHER - Revision : 2 |
2017-03-28 | PHP Exception Handling remote denial of service attempt RuleID : 41689 - Type : SERVER-OTHER - Revision : 2 |
2017-02-23 | PHP ZipArchive getFromIndex and getFromName integer overflow attempt RuleID : 41384 - Type : SERVER-WEBAPP - Revision : 2 |
2017-02-23 | PHP ZipArchive getFromIndex and getFromName integer overflow attempt RuleID : 41383 - Type : SERVER-WEBAPP - Revision : 2 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40297 - Type : FILE-IMAGE - Revision : 3 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40296 - Type : FILE-IMAGE - Revision : 2 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40295 - Type : FILE-IMAGE - Revision : 2 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40294 - Type : FILE-IMAGE - Revision : 2 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40248 - Type : FILE-IMAGE - Revision : 3 |
Nessus® Vulnerability Scanner
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id | Description |
---|---|
2019-01-14 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2019-1147.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-ee6707d519.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-b6072889db.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-1aeac808ce.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-791c3cfe21.nasl - Type : ACT_GATHER_INFO |
id | Description |
---|---|
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-7ebfe1e6f2.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-dfe1f0bac6.nasl - Type : ACT_GATHER_INFO |
2018-12-17 | Name : The remote Debian host is missing a security update. File : debian_DLA-1608.nasl - Type : ACT_GATHER_INFO |
2018-12-11 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4353.nasl - Type : ACT_GATHER_INFO |
2018-12-03 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201812-01.nasl - Type : ACT_GATHER_INFO |
2018-10-26 | Name : The remote EulerOS Virtualization host is missing a security update. File : EulerOS_SA-2018-1325.nasl - Type : ACT_GATHER_INFO |
2018-10-19 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1090.nasl - Type : ACT_GATHER_INFO |
2018-09-27 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1309.nasl - Type : ACT_GATHER_INFO |
2018-09-27 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1310.nasl - Type : ACT_GATHER_INFO |
2018-09-24 | Name : The remote Fedora host is missing a security update. File : fedora_2018-25100b492c.nasl - Type : ACT_GATHER_INFO |
2018-09-20 | Name : The remote Debian host is missing a security update. File : debian_DLA-1509.nasl - Type : ACT_GATHER_INFO |
2018-09-18 | Name : The remote EulerOS Virtualization host is missing a security update. File : EulerOS_SA-2018-1249.nasl - Type : ACT_GATHER_INFO |
2018-09-04 | Name : The remote Debian host is missing a security update. File : debian_DLA-1490.nasl - Type : ACT_GATHER_INFO |
2018-08-24 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1066.nasl - Type : ACT_GATHER_INFO |
2018-08-24 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1067.nasl - Type : ACT_GATHER_INFO |
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2017-0021.nasl - Type : ACT_GATHER_INFO |
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2017-0029.nasl - Type : ACT_GATHER_INFO |
2018-08-10 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1224.nasl - Type : ACT_GATHER_INFO |
2018-07-06 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4240.nasl - Type : ACT_GATHER_INFO |
2018-07-03 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1217.nasl - Type : ACT_GATHER_INFO |