Known vulnerabilities in php-fpm - page 3
Vendor:
openEuler
Software:
php-fpm
Software CPE:
cpe:2.3:o:openeuler:php-fpm:*:*:*:*:*:openeuler:*:*
Website:
https://www.openeuler.org/
Total vulnerabilities:
71
Public exploits:
8
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
8.0.30-16
8.3.32-1
8.0.30-14
8.0.30-13
8.0.30-12
8.3.31-1
8.3.29-1
8.0.30-11
8.3.23-1
8.0.30-10
8.0.30-9
8.3.19-1
8.0.30-7
8.0.30-6
8.0.30-5
8.0.30-4
8.0.30-3
7.2.34-3
8.0.30-1
8.0.28-1
7.2.34-2
7.2.10-20
8.0.0-7
7.2.10-19
7.2.10-17
7.2.10-16
7.2.10-15
7.2.10-13
7.2.10-12
7.2.10-10
7.2.10-8
7.2.10-7
7.2.10-6
7.2.10-5
Vulnerabilities (71)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU78977 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2023-3823 |
CWE-611 | High | 7.2.34-3, 8.0.30-1 | 06.08.2023 |
SB2023080604 SB2023081704 SB20230821142 and 31 more |
||
| #VU77112 - Use of Insufficiently Random Values CVE-2023-3247 |
CWE-330 | Medium | 7.2.34-3, 8.0.30-1 | 09.06.2023 |
SB2023060919 SB2023061105 SB2023061516 and 24 more |
||
| #VU72167 - Out-of-bounds write CVE-2023-0568 |
CWE-787 | Medium | 7.2.34-3, 8.0.30-1 | 14.02.2023 |
SB2023021417 SB2023021526 SB2023022245 and 27 more |
||
| #VU72165 - Improper input validation CVE-2023-0662 |
CWE-20 | Medium | 7.2.34-3, 8.0.30-1 | 14.02.2023 |
SB2023021417 SB2023021526 SB2023022245 and 25 more |
||
| #VU70788 - Integer overflow CVE-2022-31631 |
CWE-190 | Medium | 7.2.34-3, 8.0.30-1 | 07.01.2023 |
SB2023010702 SB2023010704 SB2023011201 and 21 more |
||
| #VU68887 - Integer overflow CVE-2022-37454 |
CWE-190 | High | 7.2.34-2, 8.0.28-1 | 01.11.2022 |
SB2022110118 SB2022110119 SB2022110209 and 69 more |
||
| #VU67756 - Security Features CVE-2022-31629 |
CWE-254 | Low | 7.2.34-2, 8.0.28-1, 8.0.30-5 | 29.09.2022 |
SB2022092960 SB2022093041 SB2022101944 and 49 more |
||
| #VU67755 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-31628 |
CWE-835 | Medium | 7.2.34-2, 8.0.28-1, 8.0.30-1 | 29.09.2022 |
SB2022092960 SB2022093041 SB2022101944 and 26 more |
||
| #VU64232 - Use of Uninitialized Resource CVE-2022-31625 |
CWE-908 | High | 7.2.10-20 | 14.06.2022 |
SB2022061403 SB2022061404 SB2022061529 and 23 more |
||
| #VU64231 - Memory corruption CVE-2022-31626 |
CWE-119 | High | 7.2.10-20 | 14.06.2022 |
SB2022061403 SB2022061404 SB2022061529 and 25 more |
||
| #VU60707 - Use After Free CVE-2021-21708 |
CWE-416 | Medium | 8.0.0-7 | 18.02.2022 |
SB2022021804 SB2022021813 SB2022022118 and 19 more |
||
| #VU58331 - Improper input validation CVE-2021-21707 |
CWE-20 | Medium | 7.2.10-17 | 23.11.2021 |
SB2021112317 SB2021112318 SB2022011821 and 21 more |
||
| #VU57656 - Out-of-bounds write CVE-2021-21703 |
CWE-787 | Low | 7.2.10-16 | 26.10.2021 |
SB2021102621 SB2021102719 SB2022012745 and 20 more |
||
| #VU54566 - Stack-based buffer overflow CVE-2021-21704 |
CWE-121 | High | 7.2.10-15 | 06.07.2021 |
SB2021070611 SB2021070612 SB2021070613 and 17 more |
||
| #VU54565 - Server-Side Request Forgery (SSRF) CVE-2021-21705 |
CWE-918 | Medium | 7.2.10-15 | 06.07.2021 |
SB2021070611 SB2021070612 SB2021070613 and 21 more |
||
| #VU47252 - Improper input validation CVE-2020-7070 |
CWE-20 | Medium | 7.2.10-12, 7.2.10-13 | 02.10.2020 |
SB2020100201 SB2020100221 SB2020102043 and 16 more |
||
| #VU26979 - Out-of-bounds read CVE-2020-7067 |
CWE-125 | Medium | 7.2.10-19 | 16.04.2020 |
SB2020041609 SB2020051426 SB2020051427 and 5 more |
||
| #VU21274 - Out-of-bounds read CVE-2019-11038 |
CWE-125 | Medium | 7.2.10-19 | 23.09.2019 |
SB2019092305 SB2019072508 SB2019110109 and 11 more |
||
| #VU19278 - Out-of-bounds read CVE-2019-11040 |
CWE-125 | Medium | 7.2.10-19 | 22.07.2019 |
SB2019072201 SB2019092105 SB2019092305 and 8 more |
||
| #VU19277 - Integer overflow CVE-2019-11039 |
CWE-190 | Medium | 7.2.10-19 | 22.07.2019 |
SB2019072201 SB2019092105 SB2019092305 and 8 more |
Showing elements 41 - 60 out of 71