PHP是PHP开源的一种在服务器端执行的脚本语言。 PHP 8.4.21之前版本和8.5.6之前版本存在缓冲区错误漏洞,该漏洞源于当包含嵌入NUL字节的编码名称传递给mb_convert_encoding()或相关mbstring函数时,代码错误地假设strncasecmp()返回0意味着字符串长度相同,可能导致全局内存越界读取,从而引发崩溃或信息泄露。以下版本受到影响:8.4.21之前版本和8.5.6之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6722 | 9.5 CRITICAL | Use-After-Free in SOAP using Apache map |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | |
| CVE-2026-7262 | NULL pointer dereference in SOAP apache:Map decoder with missing <value> | |
| CVE-2026-7261 | SoapServer session-persisted object use-after-free via SOAP header fault | |
| CVE-2026-7259 | Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() | |
| CVE-2026-7568 | Signed integer overflow in metaphone() | |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | |
| CVE-2026-7263 | DoS attack via DOMNode::C14N() |
No comments yet