目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

PHP Group 厂商漏洞列表 / CVE 中文分析 91

PHP Group 厂商相关 91 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

PHP Group 主要致力于 PHP 编程语言的维护与开发,其核心项目包括 PHP 解释器及 PECL 扩展库。截至最新统计,该厂商已收录 78 条 CVE,历史漏洞多集中于远程代码执行、缓冲区溢出及逻辑缺陷,部分源于对输入数据校验不严或内存管理不当。值得关注的是,随着 PHP 8 的普及,类型系统强化提升了代码安全性,但旧版本因缺乏持续维护仍面临较高风险,建议用户及时升级以规避已知安全隐患。

上位製品 PHP Group: PHP PHP Imagick extension
CVE IDタイトルCVSS深刻度公開日
CVE-2026-7260 Stack overflow in phar with circular symlinks — PHPCWE-121 5.4 Medium2026-07-30
CVE-2026-17544 Out-of-bounds write in bccomp() via crafted operand and scale — PHPCWE-787 8.1 High2026-07-30
CVE-2026-17543 SQL injection in ext-pgsql via E'...' backslash breakout — PHPCWE-89 8.1 High2026-07-30
CVE-2026-7263 DoS attack via DOMNode::C14N() — PHPCWE-404 7.5 -2026-05-10
CVE-2026-6104 Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding — PHPCWE-125 9.1 -2026-05-10
CVE-2026-7258 Out-of-bounds read in urldecode() on NetBSD — PHPCWE-125 7.5 -2026-05-10
CVE-2026-6722 Use-After-Free in SOAP using Apache map — PHPCWE-416 9.5 Critical2026-05-10
CVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() — PHPCWE-476 7.5 -2026-05-10
CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault — PHPCWE-416 8.8 -2026-05-10
CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value> — PHPCWE-476 7.5 -2026-05-10
CVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted strings — PHPCWE-89 9.8 -2026-05-10
CVE-2026-7568 Signed integer overflow in metaphone() — PHPCWE-190 9.1 -2026-05-10
CVE-2026-6735 XSS within PHP-FPM status endpoint — PHPCWE-79 6.1 -2026-05-10
CVE-2025-14177 Information Leak of Memory in getimagesize — PHPCWE-125 9.1 -2025-12-27
CVE-2025-14178 Heap buffer overflow in array_merge() — PHPCWE-787 6.5 Medium2025-12-27
CVE-2025-14180 NULL Pointer Dereference in PDO quoting — PHPCWE-476 7.5 -2025-12-27
CVE-2025-1735 pgsql extension does not check for errors during escaping — PHPCWE-89 5.9 Medium2025-07-13
CVE-2025-1220 Null byte termination in hostnames — PHPCWE-918 3.7 Low2025-07-13
CVE-2025-6491 NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix — PHPCWE-476 5.9 Medium2025-07-13
CVE-2024-11235 Reference counting in php_request_shutdown causes Use-After-Free — PHPCWE-416 9.8AICriticalAI2025-04-04
CVE-2025-1861 Stream HTTP wrapper truncates redirect location to 1024 bytes — PHPCWE-131 6.5 -2025-03-30
CVE-2025-1736 Stream HTTP wrapper header check might omit basic auth header — PHPCWE-20 5.3 -2025-03-30
CVE-2025-1734 Streams HTTP wrapper does not fail for headers with invalid name and no colon — PHPCWE-20 7.5 -2025-03-30
CVE-2025-1219 libxml streams use wrong content-type header when requesting a redirected resource — PHP 8.1 -2025-03-30
CVE-2025-1217 Header parser of http stream wrapper does not handle folded headers — PHPCWE-20 7.5 -2025-03-29
CVE-2022-31631 PDO::quote() may return unquoted string — PHPCWE-74 9.1 Critical2025-02-12
CVE-2024-11233 Single byte overread with convert.quoted-printable-decode filter — PHPCWE-122 4.8 Medium2024-11-24
CVE-2024-11234 Configuring a proxy in a stream context might allow for CRLF injection in URIs — PHPCWE-20 4.8 Medium2024-11-24
CVE-2024-11236 Integer overflow in the firebird and dblib quoters causing OOB writes — PHPCWE-787 9.8 Critical2024-11-24
CVE-2024-8929 Leak partial content of the heap through heap buffer over-read in mysqlnd — PHPCWE-200 5.8 Medium2024-11-22

本页汇总了 PHP Group 厂商截至目前公开的全部 91 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。