PHP是PHP开源的一种在服务器端执行的脚本语言。 PHP 8.2.31之前版本、8.3.31之前版本、8.4.21之前版本和8.5.6之前版本存在缓冲区错误漏洞,该漏洞源于metaphone()函数使用有符号整数变量跟踪输入字符串中的当前位置,当传递超过2147483647字节的字符串时发生有符号整数溢出,导致未定义行为,可能引发越界读取造成段错误或访问无关内存,影响PHP进程的可用性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6722 | 9.5 CRITICAL | Use-After-Free in SOAP using Apache map |
| CVE-2026-7258 | Out-of-bounds read in urldecode() on NetBSD | |
| CVE-2026-7262 | NULL pointer dereference in SOAP apache:Map decoder with missing <value> | |
| CVE-2026-7261 | SoapServer session-persisted object use-after-free via SOAP header fault | |
| CVE-2026-7259 | Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() | |
| CVE-2026-6735 | XSS within PHP-FPM status endpoint | |
| CVE-2025-14179 | SQL injection in pdo_firebird via NUL bytes in quoted strings | |
| CVE-2026-7263 | DoS attack via DOMNode::C14N() | |
| CVE-2026-6104 | Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding |
No comments yet