This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
Summuary | |
---|---|
CPE Name | cpe:/a:php:php:5.5.14:rc1 |
Detail | |||
---|---|---|---|
Vendor | Php | First view | 2013-08-13 |
Product | Php | Last view | 2019-03-08 |
Version | 5.5.14 | Type | Application |
Edition | |||
Language | |||
Update | rc1 | ||
CPE Product | cpe:/a:php:php |
Activity : Overall
Related : CVE
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
7.5 | 2019-03-08 | CVE-2019-9641 | Network | Low | None Requ... | |
5 | 2019-03-08 | CVE-2019-9639 | Network | Low | None Requ... | |
5 | 2019-03-08 | CVE-2019-9638 | Network | Low | None Requ... | |
5 | 2019-03-08 | CVE-2019-9637 | Network | Low | None Requ... | |
5 | 2019-02-22 | CVE-2019-9024 | Network | Low | None Requ... | |
Date | Alert | Access Vector | Access Complexity | Authentication | ||
---|---|---|---|---|---|---|
7.5 | 2019-02-22 | CVE-2019-9023 | Network | Low | None Requ... | |
7.5 | 2019-02-22 | CVE-2019-9021 | Network | Low | None Requ... | |
7.5 | 2019-02-22 | CVE-2019-9020 | Network | Low | None Requ... | |
6.8 | 2019-01-26 | CVE-2019-6977 | Network | Medium | None Requ... | |
5 | 2018-12-07 | CVE-2018-19935 | Network | Low | None Requ... | |
5 | 2018-11-20 | CVE-2018-19396 | Network | Low | None Requ... | |
4.3 | 2018-09-16 | CVE-2018-17082 | Network | Medium | None Requ... | |
5 | 2018-08-03 | CVE-2018-14883 | Network | Low | None Requ... | |
4.3 | 2018-08-02 | CVE-2018-14851 | Network | Medium | None Requ... | |
6.8 | 2018-04-29 | CVE-2018-10549 | Network | Medium | None Requ... | |
5 | 2018-04-29 | CVE-2018-10548 | Network | Low | None Requ... | |
4.3 | 2018-04-29 | CVE-2018-10547 | Network | Medium | None Requ... | |
5 | 2018-04-29 | CVE-2018-10546 | Network | Low | None Requ... | |
1.9 | 2018-04-29 | CVE-2018-10545 | Local | Medium | None Requ... | |
7.5 | 2018-03-01 | CVE-2018-7584 | Network | Low | None Requ... | |
6.8 | 2018-02-19 | CVE-2015-9253 | Network | Low | Requires ... | |
5 | 2018-02-09 | CVE-2016-10712 | Network | Low | None Requ... | |
4.3 | 2018-01-16 | CVE-2018-5712 | Network | Medium | None Requ... | |
4.3 | 2018-01-16 | CVE-2018-5711 | Network | Medium | None Requ... |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
26% (32) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
13% (16) | CWE-125 | Out-of-bounds Read |
8% (10) | CWE-416 | Use After Free |
7% (9) | CWE-190 | Integer Overflow or Wraparound |
6% (8) | CWE-476 | NULL Pointer Dereference |
% | id | Name |
---|---|---|
6% (8) | CWE-20 | Improper Input Validation |
4% (6) | CWE-787 | Out-of-bounds Write |
4% (6) | CWE-189 | Numeric Errors |
4% (5) | CWE-200 | Information Exposure |
2% (3) | CWE-502 | Deserialization of Untrusted Data |
2% (3) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
1% (2) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
1% (2) | CWE-264 | Permissions, Privileges, and Access Controls |
1% (2) | CWE-74 | Failure to Sanitize Data into a Different Plane ('Injection') |
0% (1) | CWE-770 | Allocation of Resources Without Limits or Throttling |
0% (1) | CWE-754 | Improper Check for Unusual or Exceptional Conditions |
0% (1) | CWE-681 | Incorrect Conversion between Numeric Types |
0% (1) | CWE-415 | Double Free |
0% (1) | CWE-399 | Resource Management Errors |
0% (1) | CWE-362 | Race Condition |
0% (1) | CWE-310 | Cryptographic Issues |
0% (1) | CWE-284 | Access Control (Authorization) Issues |
0% (1) | CWE-17 | Code |
Oval Markup Language : Definitions
OvalID | Name |
---|---|
oval:org.mitre.oval:def:29013 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:28496 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:29027 | HP-UX Apache Server Suite running Apache Tomcat or PHP, Remote Denial of Ser... |
oval:org.mitre.oval:def:28921 | SUSE-SU-2015:0866-1 -- Security update for gd (low) |
oval:org.mitre.oval:def:24951 | DSA-2961-1 php5 - security update |
id | Name |
---|---|
oval:org.mitre.oval:def:24930 | USN-2254-2 -- php5 updates |
oval:org.mitre.oval:def:24159 | USN-2254-1 -- php5 vulnerabilities |
oval:org.mitre.oval:def:26689 | DSA-3008-1 php5 - security update |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2014-B-0086 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0052897 |
2013-B-0093 | Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0040108 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-10-23 | PHP http fopen stack buffer overflow attempt RuleID : 51578 - Type : SERVER-WEBAPP - Revision : 1 |
2019-05-07 | PHP gdImageColorMatch heap buffer overflow file download attempt RuleID : 49673 - Type : SERVER-OTHER - Revision : 1 |
2019-05-07 | PHP gdImageColorMatch heap buffer overflow file upload attempt RuleID : 49672 - Type : SERVER-OTHER - Revision : 1 |
2018-12-11 | CVE PHP infinite loop from use of stream filter and convert.iconv file upload... RuleID : 48354 - Type : SERVER-WEBAPP - Revision : 2 |
2018-06-26 | PHP .phar cross site scripting attempt RuleID : 46808 - Type : SERVER-WEBAPP - Revision : 2 |
Date | Description |
---|---|
2017-07-18 | Oniguruma expression parser out of bounds write attempt RuleID : 43182 - Type : FILE-OTHER - Revision : 2 |
2017-07-18 | Oniguruma expression parser out of bounds write attempt RuleID : 43181 - Type : FILE-OTHER - Revision : 2 |
2017-02-23 | PHP ZipArchive getFromIndex and getFromName integer overflow attempt RuleID : 41384 - Type : SERVER-WEBAPP - Revision : 2 |
2017-02-23 | PHP ZipArchive getFromIndex and getFromName integer overflow attempt RuleID : 41383 - Type : SERVER-WEBAPP - Revision : 2 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40297 - Type : FILE-IMAGE - Revision : 3 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40296 - Type : FILE-IMAGE - Revision : 2 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40295 - Type : FILE-IMAGE - Revision : 2 |
2016-11-01 | PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt RuleID : 40294 - Type : FILE-IMAGE - Revision : 2 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40248 - Type : FILE-IMAGE - Revision : 3 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40247 - Type : FILE-IMAGE - Revision : 2 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40246 - Type : FILE-IMAGE - Revision : 3 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40245 - Type : FILE-IMAGE - Revision : 2 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40244 - Type : FILE-IMAGE - Revision : 2 |
2016-10-20 | PHP exif_process_user_comment null pointer dereference attempt RuleID : 40243 - Type : FILE-IMAGE - Revision : 2 |
2016-10-11 | PHP locale_accept_from_http out of bounds read attempt RuleID : 40046 - Type : SERVER-OTHER - Revision : 2 |
2016-10-11 | PHP unserialize var_hash use-after-free attempt RuleID : 40038 - Type : SERVER-WEBAPP - Revision : 2 |
2016-07-28 | HttpOxy CGI application vulnerability potential man-in-the-middle attempt RuleID : 39737-community - Type : SERVER-WEBAPP - Revision : 2 |
2016-08-31 | HttpOxy CGI application vulnerability potential man-in-the-middle attempt RuleID : 39737 - Type : SERVER-WEBAPP - Revision : 2 |
2014-11-16 | PHP DNS parsing heap overflow attempt RuleID : 31460 - Type : SERVER-WEBAPP - Revision : 3 |
Nessus® Vulnerability Scanner
This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id | Description |
---|---|
2019-01-14 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2019-1147.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-ee6707d519.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-b6072889db.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-1aeac808ce.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-791c3cfe21.nasl - Type : ACT_GATHER_INFO |
id | Description |
---|---|
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-7ebfe1e6f2.nasl - Type : ACT_GATHER_INFO |
2019-01-03 | Name : The remote Fedora host is missing a security update. File : fedora_2018-dfe1f0bac6.nasl - Type : ACT_GATHER_INFO |
2018-12-17 | Name : The remote Debian host is missing a security update. File : debian_DLA-1608.nasl - Type : ACT_GATHER_INFO |
2018-12-11 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4353.nasl - Type : ACT_GATHER_INFO |
2018-12-03 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201812-01.nasl - Type : ACT_GATHER_INFO |
2018-10-26 | Name : The remote EulerOS Virtualization host is missing a security update. File : EulerOS_SA-2018-1325.nasl - Type : ACT_GATHER_INFO |
2018-10-19 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1090.nasl - Type : ACT_GATHER_INFO |
2018-09-27 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1309.nasl - Type : ACT_GATHER_INFO |
2018-09-27 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1310.nasl - Type : ACT_GATHER_INFO |
2018-09-24 | Name : The remote Fedora host is missing a security update. File : fedora_2018-25100b492c.nasl - Type : ACT_GATHER_INFO |
2018-09-20 | Name : The remote Debian host is missing a security update. File : debian_DLA-1509.nasl - Type : ACT_GATHER_INFO |
2018-09-18 | Name : The remote EulerOS Virtualization host is missing a security update. File : EulerOS_SA-2018-1249.nasl - Type : ACT_GATHER_INFO |
2018-09-04 | Name : The remote Debian host is missing a security update. File : debian_DLA-1490.nasl - Type : ACT_GATHER_INFO |
2018-08-24 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1066.nasl - Type : ACT_GATHER_INFO |
2018-08-24 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1067.nasl - Type : ACT_GATHER_INFO |
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2017-0021.nasl - Type : ACT_GATHER_INFO |
2018-08-17 | Name : The remote PhotonOS host is missing multiple security updates. File : PhotonOS_PHSA-2017-0029.nasl - Type : ACT_GATHER_INFO |
2018-08-10 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1224.nasl - Type : ACT_GATHER_INFO |
2018-07-06 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-4240.nasl - Type : ACT_GATHER_INFO |
2018-07-03 | Name : The remote EulerOS host is missing a security update. File : EulerOS_SA-2018-1217.nasl - Type : ACT_GATHER_INFO |