Known vulnerabilities in php7.4 (Debian package)
Vendor:
Debian
Software:
php7.4 (Debian package)
Software CPE:
cpe:2.3:o:debian:php7_4_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
18
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
7.4.14-1
7.4.15-1
7.4.15-2
7.4.15-3
7.4.15-5+deb11u1
7.4.16-1
7.4.18-1
7.4.20-1
7.4.21-1+deb11u1
7.4.26-1
7.4.33-1+deb11u6
7.4.33-1+deb11u7
7.4.33-1+deb11u8
7.4.33-1+deb11u9
7.4.33-1+deb11u5
7.4.33-1+deb11u4
7.4.33-1+deb11u3
7.4.33-1+deb11u1
7.4.25-1+deb11u1
7.4.30-1+deb11u1
7.4.28-1+deb11u1
7.4.11
7.4.11-1
7.4.10
7.4.10-1
7.4.9-2
7.4.9
7.4.9-1
7.4.5
7.4.3
7.4.5-1
7.4.3-3
7.4.3-4
7.4.3-1
7.4.1-1
7.4.2-7
7.4.0~rc6-1
Vulnerabilities (18)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU88484 - Improper Authentication CVE-2024-3096 |
CWE-287 | High | 7.4.33-1+deb11u5 | 11.04.2024 |
SB2024041173 SB2024041175 SB2024041176 and 25 more |
||
| #VU88483 - Security Features CVE-2024-2756 |
CWE-254 | Low | 7.4.33-1+deb11u5 | 11.04.2024 |
SB2024041173 SB2024041175 SB2024041176 and 24 more |
||
| #VU78978 - Memory corruption CVE-2023-3824 |
CWE-119 | Critical | 7.4.33-1+deb11u5 | 06.08.2023 |
SB2023080604 SB2023081704 SB20230821142 and 32 more |
||
| #VU78977 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2023-3823 |
CWE-611 | High | 7.4.33-1+deb11u5 | 06.08.2023 |
SB2023080604 SB2023081704 SB20230821142 and 31 more |
||
| #VU77112 - Use of Insufficiently Random Values CVE-2023-3247 |
CWE-330 | Medium | 7.4.33-1+deb11u4 | 09.06.2023 |
SB2023060919 SB2023061105 SB2023061516 and 24 more |
||
| #VU72167 - Out-of-bounds write CVE-2023-0568 |
CWE-787 | Medium | 7.4.33-1+deb11u3 | 14.02.2023 |
SB2023021417 SB2023021526 SB2023022245 and 27 more |
||
| #VU72166 - Use of Insufficiently Random Values CVE-2023-0567 |
CWE-330 | Medium | 7.4.33-1+deb11u3 | 14.02.2023 |
SB2023021417 SB2023021526 SB2023022245 and 23 more |
||
| #VU72165 - Improper input validation CVE-2023-0662 |
CWE-20 | Medium | 7.4.33-1+deb11u3 | 14.02.2023 |
SB2023021417 SB2023021526 SB2023022245 and 25 more |
||
| #VU70788 - Integer overflow CVE-2022-31631 |
CWE-190 | Medium | 7.4.33-1+deb11u3 | 07.01.2023 |
SB2023010702 SB2023010704 SB2023011201 and 21 more |
||
| #VU68887 - Integer overflow CVE-2022-37454 |
CWE-190 | High | 7.4.33-1+deb11u1 | 01.11.2022 |
SB2022110118 SB2022110119 SB2022110209 and 69 more |
||
| #VU68886 - Out-of-bounds read CVE-2022-31630 |
CWE-125 | Medium | 7.4.33-1+deb11u1 | 01.11.2022 |
SB2022110119 SB2022110336 SB2022110814 and 21 more |
||
| #VU67756 - Security Features CVE-2022-31629 |
CWE-254 | Low | 7.4.33-1+deb11u1 | 29.09.2022 |
SB2022092960 SB2022093041 SB2022101944 and 49 more |
||
| #VU67755 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-31628 |
CWE-835 | Medium | 7.4.33-1+deb11u1 | 29.09.2022 |
SB2022092960 SB2022093041 SB2022101944 and 26 more |
||
| #VU64232 - Use of Uninitialized Resource CVE-2022-31625 |
CWE-908 | High | 7.4.30-1+deb11u1 | 14.06.2022 |
SB2022061403 SB2022061404 SB2022061529 and 23 more |
||
| #VU64231 - Memory corruption CVE-2022-31626 |
CWE-119 | High | 7.4.30-1+deb11u1 | 14.06.2022 |
SB2022061403 SB2022061404 SB2022061529 and 25 more |
||
| #VU60707 - Use After Free CVE-2021-21708 |
CWE-416 | Medium | 7.4.28-1+deb11u1 | 18.02.2022 |
SB2022021804 SB2022021813 SB2022022118 and 19 more |
||
| #VU58331 - Improper input validation CVE-2021-21707 |
CWE-20 | Medium | 7.4.28-1+deb11u1 | 23.11.2021 |
SB2021112317 SB2021112318 SB2022011821 and 21 more |
||
| #VU57656 - Out-of-bounds write CVE-2021-21703 |
CWE-787 | Low | 7.4.25-1+deb11u1 | 26.10.2021 |
SB2021102621 SB2021102719 SB2022012745 and 20 more |