Known vulnerabilities in php7.0 (Ubuntu package)
Vendor:
Canonical Ltd.
Software:
php7.0 (Ubuntu package)
Software CPE:
cpe:2.3:o:canonical:php70_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Website:
https://www.ubuntu.com/
Total vulnerabilities:
35
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
7.0.33-0ubuntu0.16.04.16+esm19
7.0.33-0ubuntu0.16.04.16+esm18
7.2.24-0ubuntu0.18.04.17+esm11
7.4.3-4ubuntu2.29+esm2
7.0.33-0ubuntu0.16.04.16+esm16
7.2.24-0ubuntu0.18.04.17+esm9
7.4.3-4ubuntu2.29+esm1
7.0.33-0ubuntu0.16.04.16+esm15
7.2.24-0ubuntu0.18.04.17+esm8
Ubuntu Pro
7.0.33-0ubuntu0.16.04.16
7.0.33-0ubuntu0.16.04.15
7.0.33
7.0.4
7.0.33-0ubuntu0.16.04.14
7.0.33-0ubuntu0.16.04.12
7.0.33-0ubuntu0.16.04.11
7.0.33-0ubuntu0.16.04.9
7.0.33-0ubuntu0.16.04.7
7.0.33-0ubuntu0.16.04.6
7.0.33-0ubuntu0.16.04.5
7.0.33-0ubuntu0.16.04.4
7.0.33-0ubuntu0.16.04.3
7.0.33-0ubuntu0.16.04.2
7.0.33-0ubuntu0.16.04.1
7.0.32-0ubuntu0.16.04.1
7.0.30-0ubuntu0.16.04.1
7.0.28-0ubuntu0.16.04.1
7.0.25-0ubuntu0.17.04.1
7.0.25-0ubuntu0.16.04.1
7.0.22-0ubuntu0.17.04.1
7.0.22-0ubuntu0.16.04.1
7.0.0~beta2-1
7.0.0~beta2-2
7.0.0~beta2-3
7.0.0~beta2-4
7.0.0~beta2-5
7.0.0~beta2-6
7.0.0~beta2-7
7.0.0~beta3-1
7.0.0~beta3-2
7.0.0~beta3-3
7.0.0~beta3-4
7.0.0~beta3-5
7.0.0~rc1-1
7.0.0~rc2-1
7.0.0~rc2-2
7.0.0~rc3-1
7.0.0~rc3-2
7.0.0~rc3-3
7.0.0~rc4-1
7.0.0~rc5-1
7.0.0~rc5-2
7.0.0~rc6-1
7.0.0~rc8-1
7.0.0~rc8-2
7.0.0~rc8-3
7.0.4-7ubuntu4
7.0.4-7ubuntu3
7.0.16-1
7.0.16-2
7.0.16-3
7.0.16-4
7.0.17-1
7.0.17-2
7.0.17-3
7.0.18-1
7.0.18-2
7.0.18-2ubuntu1
7.0.18-0ubuntu0.17.04.1
7.0.18-0ubuntu0.16.10.1
7.0.18-0ubuntu0.16.04.1
7.0.15-1ubuntu4
7.0.15-1ubuntu3
7.0.15-1ubuntu2
7.0.15-1
7.0.15-1ubuntu1
7.0.15-0ubuntu0.16.10.4
7.0.15-0ubuntu0.16.10.3
7.0.15-0ubuntu0.16.10.2
7.0.15-0ubuntu0.16.10.1
7.0.15-0ubuntu0.16.04.4
7.0.15-0ubuntu0.16.04.3
7.0.15-0ubuntu0.16.04.2
7.0.15-0ubuntu0.16.04.1
7.0.13-3
7.0.14-1
7.0.14-2
7.0.14-2ubuntu1
7.0.13-1
7.0.13-2
7.0.13-2ubuntu1
7.0.13-0ubuntu0.16.10.1
7.0.3-5ubuntu1
7.0.3-7ubuntu1
7.0.3-9ubuntu1
7.0.3-9ubuntu2
7.0.4-5ubuntu1
7.0.4-5ubuntu2
7.0.4-7ubuntu1
7.0.4-7ubuntu2
7.0.4-7ubuntu2.1
7.0.8-0ubuntu0.16.04.1
7.0.8-0ubuntu0.16.04.2
7.0.8-0ubuntu0.16.04.3
7.0.13-0ubuntu0.16.04.1
7.0.12-2ubuntu2
7.0.0-1
7.0.0-2
7.0.0-3
7.0.0-4
7.0.0-5
7.0.0-6
7.0.1-1
7.0.1-2
7.0.1-3
7.0.1-4
7.0.1-5
7.0.1-6
7.0.2-1
7.0.2-2
7.0.2-3
7.0.2-4
7.0.2-5
7.0.3-1
7.0.3-2
7.0.3-3
7.0.3-4
7.0.3-5
7.0.3-6
7.0.3-7
7.0.3-8
7.0.3-9
7.0.3-10
7.0.3-11
7.0.3-12
7.0.3-13
7.0.4-1
7.0.4-2
7.0.4-3
7.0.4-4
7.0.4-5
7.0.4-6
7.0.4-7
7.0.5-1
7.0.5-2
7.0.5-3
7.0.5-4
7.0.6-1
7.0.6-2
7.0.6-3
7.0.6-4
7.0.6-5
7.0.6-6
7.0.6-7
7.0.6-8
7.0.6-9
7.0.6-10
7.0.6-11
7.0.6-12
7.0.6-13
7.0.7-1
7.0.7-2
7.0.7-3
7.0.7-4
7.0.7-4ubuntu1
7.0.7-4ubuntu2
7.0.7-5
7.0.8-1
7.0.8-2
7.0.8-3
7.0.8-3ubuntu1
7.0.8-3ubuntu2
7.0.8-3ubuntu3
7.0.8-4
7.0.8-5
7.0.9-1
7.0.9-2
7.0.10-1
7.0.10-2
7.0.10-3
7.0.11-1
7.0.11-2
7.0.12-1
7.0.12-2
7.0.12-2ubuntu1
Vulnerabilities (35)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU130912 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2025-14179 |
CWE-89 | High | 7.0.33-0ubuntu0.16.04.16+esm19 | 10.05.2026 |
SB2026051001 SB20260511112 SB20260513120 and 19 more |
||
| #VU130913 - Use After Free CVE-2026-6722 |
CWE-416 | Medium | 7.0.33-0ubuntu0.16.04.16+esm19 | 10.05.2026 |
SB2026051001 SB20260511112 SB20260513120 and 17 more |
||
| #VU130914 - Use After Free CVE-2026-7261 |
CWE-416 | Medium | 7.0.33-0ubuntu0.16.04.16+esm19 | 10.05.2026 |
SB2026051001 SB20260511112 SB20260513120 and 17 more |
||
| #VU112190 - Server-Side Request Forgery (SSRF) CVE-2025-1220 |
CWE-918 | Medium | 7.0.33-0ubuntu0.16.04.16+esm16, 7.0.33-0ubuntu0.16.04.16+esm18, 7.2.24-0ubuntu0.18.04.17+esm9, 7.2.24-0ubuntu0.18.04.17+esm11, 7.4.3-4ubuntu2.29+esm1, 7.4.3-4ubuntu2.29+esm2 | 04.07.2025 |
SB2025070427 SB2025070433 SB2025070434 and 16 more |
||
| #VU112189 - NULL Pointer Dereference CVE-2025-6491 |
CWE-476 | Medium | 7.0.33-0ubuntu0.16.04.16+esm16, 7.0.33-0ubuntu0.16.04.16+esm18, 7.2.24-0ubuntu0.18.04.17+esm9, 7.2.24-0ubuntu0.18.04.17+esm11, 7.4.3-4ubuntu2.29+esm1, 7.4.3-4ubuntu2.29+esm2 | 04.07.2025 |
SB2025070427 SB2025070433 SB2025070434 and 18 more |
||
| #VU112187 - Error Handling CVE-2025-1735 |
CWE-388 | Medium | 7.0.33-0ubuntu0.16.04.16+esm16, 7.0.33-0ubuntu0.16.04.16+esm18, 7.2.24-0ubuntu0.18.04.17+esm9, 7.2.24-0ubuntu0.18.04.17+esm11, 7.4.3-4ubuntu2.29+esm1, 7.4.3-4ubuntu2.29+esm2 | 04.07.2025 |
SB2025070427 SB2025070433 SB2025070434 and 17 more |
||
| #VU105644 - Improper input validation CVE-2025-1217 |
CWE-20 | Medium | 7.0.33-0ubuntu0.16.04.16+esm15, 7.2.24-0ubuntu0.18.04.17+esm8 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105643 - Improper input validation CVE-2025-1734 |
CWE-20 | Medium | 7.0.33-0ubuntu0.16.04.16+esm15, 7.2.24-0ubuntu0.18.04.17+esm8 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105642 - Improper input validation CVE-2025-1861 |
CWE-20 | Low | 7.0.33-0ubuntu0.16.04.16+esm15, 7.2.24-0ubuntu0.18.04.17+esm8 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU105641 - Improper Authentication CVE-2025-1736 |
CWE-287 | Medium | 7.0.33-0ubuntu0.16.04.16+esm15, 7.2.24-0ubuntu0.18.04.17+esm8 | 12.03.2025 |
SB2025031234 SB2025031232 SB2025031231 and 21 more |
||
| #VU100674 - Buffer over-read CVE-2024-11233 |
CWE-126 | Medium | Ubuntu Pro | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 16 more |
||
| #VU100673 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2024-11234 |
CWE-93 | Medium | Ubuntu Pro | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 15 more |
||
| #VU100672 - Integer overflow CVE-2024-11236 |
CWE-190 | High | Ubuntu Pro | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 12 more |
||
| #VU100671 - Buffer over-read CVE-2024-8929 |
CWE-126 | Medium | Ubuntu Pro | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 15 more |
||
| #VU100670 - Out-of-bounds read CVE-2024-8932 |
CWE-125 | Medium | Ubuntu Pro | 19.11.2024 |
SB2024111985 SB2024112137 SB2024112138 and 11 more |
||
| #VU91107 - Improper input validation CVE-2024-5458 |
CWE-20 | Medium | Ubuntu Pro | 05.06.2024 |
SB2024060501 SB2024060502 SB2024060503 and 18 more |
||
| #VU88484 - Improper Authentication CVE-2024-3096 |
CWE-287 | High | Ubuntu Pro | 11.04.2024 |
SB2024041173 SB2024041175 SB2024041176 and 25 more |
||
| #VU88483 - Security Features CVE-2024-2756 |
CWE-254 | Low | Ubuntu Pro | 11.04.2024 |
SB2024041173 SB2024041175 SB2024041176 and 24 more |
||
| #VU78977 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2023-3823 |
CWE-611 | High | Ubuntu Pro | 06.08.2023 |
SB2023080604 SB2023081704 SB20230821142 and 31 more |
||
| #VU74185 - Memory corruption CVE-2022-4900 |
CWE-119 | Low | Ubuntu Pro | 30.03.2023 |
SB2023033010 SB2023033014 SB2023041468 and 4 more |
Showing elements 1 - 20 out of 35