Known vulnerabilities in php-mbstring - page 3

Vendor: OpenAnolis
Software: php-mbstring
Software CPE: cpe:2.3:o:openanolis:php-mbstring:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 53
Public exploits: 11
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting php-mbstring php-mbstring is affected by 53 known vulnerabilities: 2 critical, 12 high, 32 medium, 7 low Critical High Medium Low

Vulnerabilities (53)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78978 - Memory corruption
CVE-2023-3824
CWE-119 Critical
Available
Exploited
7.4.33-2.0.1, 8.0.30-1.0.1, 8.2.10-1 06.08.2023 SB2023080604
SB2023081704
SB20230821142
and 32 more
#VU70788 - Integer overflow
CVE-2022-31631
CWE-190 Medium
No
No
7.4.33-1.0.1 07.01.2023 SB2023010702
SB2023010704
SB2023011201
and 21 more
#VU68887 - Integer overflow
CVE-2022-37454
CWE-190 High
Available
No
7.4.33-1.0.1 01.11.2022 SB2022110118
SB2022110119
SB2022110209
and 69 more
#VU68886 - Out-of-bounds read
CVE-2022-31630
CWE-125 Medium
No
No
7.4.33-1.0.1 01.11.2022 SB2022110119
SB2022110336
SB2022110814
and 21 more
#VU67756 - Security Features
CVE-2022-31629
CWE-254 Low
Available
No
7.4.33-1.0.1, 7.4.33-2.0.1, 8.2.20-1 29.09.2022 SB2022092960
SB2022093041
SB2022101944
and 49 more
#VU67755 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-31628
CWE-835 Medium
No
No
7.4.33-1.0.1 29.09.2022 SB2022092960
SB2022093041
SB2022101944
and 26 more
#VU64232 - Use of Uninitialized Resource
CVE-2022-31625
CWE-908 High
No
No
7.4.19-4.0.1 14.06.2022 SB2022061403
SB2022061404
SB2022061529
and 23 more
#VU64231 - Memory corruption
CVE-2022-31626
CWE-119 High
Available
No
7.4.19-3.0.1, 8.0.13-3.0.1 14.06.2022 SB2022061403
SB2022061404
SB2022061529
and 25 more
#VU57656 - Out-of-bounds write
CVE-2021-21703
CWE-787 Low
No
No
7.4.19-2.0.1 26.10.2021 SB2021102621
SB2021102719
SB2022012745
and 20 more
#VU54565 - Server-Side Request Forgery (SSRF)
CVE-2021-21705
CWE-918 Medium
No
No
7.4.19-2.0.1 06.07.2021 SB2021070611
SB2021070612
SB2021070613
and 21 more
#VU49907 - UNIX Symbolic Link (Symlink) Following
CVE-2020-36193
CWE-61 High
Available
Exploited
7.4.19-4.0.1 18.01.2021 SB2021012112
SB2021012113
SB2021012410
and 20 more
#VU48668 - Improper input validation
CVE-2020-28949
CWE-20 High
Available
Exploited
7.4.19-4.0.1 19.11.2020 SB2020112607
SB2020112608
SB2020112609
and 20 more
#VU48669 - Deserialization of Untrusted Data
CVE-2020-28948
CWE-502 High
Available
No
7.4.19-4.0.1 19.11.2020 SB2020112607
SB2020112608
SB2020112609
and 21 more


Showing elements 41 - 60 out of 53