Known vulnerabilities in php (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:php_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 34
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting php (Red Hat package) php (Red Hat package) is affected by 34 known vulnerabilities: 1 critical, 6 high, 21 medium, 6 low Critical High Medium Low

Vulnerabilities (34)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137285 - Uncaught Exception
CVE-2026-12184
CWE-248 Medium
No
No
8.3.32-1.el10_2 09.07.2026 SB2026051001
SB2026071918
SB2026071919
and 5 more
#VU137286 - Memory corruption
CVE-2026-14355
CWE-119 Medium
No
No
8.3.32-1.el10_2 09.07.2026 SB2026070955
SB2026070956
SB2026071356
and 17 more
#VU130909 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-6735
CWE-79 Medium
No
No
8.3.31-1.el10_2 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130910 - NULL Pointer Dereference
CVE-2026-7259
CWE-476 Medium
No
No
8.3.31-1.el10_2 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 14 more
#VU130915 - NULL Pointer Dereference
CVE-2026-7262
CWE-476 Medium
No
No
8.3.31-1.el10_2 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130916 - Integer overflow
CVE-2026-7568
CWE-190 Medium
No
No
8.3.31-1.el10_2 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130917 - Type conversion
CVE-2026-7258
CWE-704 Medium
No
No
8.3.31-1.el10_2 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU120272 - Missing release of memory after effective lifetime
CVE-2025-14177
CWE-401 Medium
Available
No
8.0.30-5.el9_7, 8.3.29-1.el10_1 23.12.2025 SB2025122340
SB2025122342
SB2026010709
and 20 more
#VU120271 - Heap-based Buffer Overflow
CVE-2025-14178
CWE-122 High
No
No
8.0.13-2.el9_0.1, 8.0.30-1.el9_2.1, 8.0.30-1.el9_4.1, 8.0.30-3.el9_6.1, 8.0.30-5.el9_7, 8.3.19-1.el10_0.1, 8.3.29-1.el10_1 23.12.2025 SB2025122340
SB2025122342
SB2026010709
and 33 more
#VU120270 - NULL Pointer Dereference
CVE-2025-14180
CWE-476 Medium
No
No
8.3.19-1.el10_0.1, 8.3.29-1.el10_1 23.12.2025 SB2025122340
SB2025122342
SB2026010709
and 18 more
#VU105644 - Improper input validation
CVE-2025-1217
CWE-20 Medium
No
No
8.0.30-3.el9_6 12.03.2025 SB2025031234
SB2025031232
SB2025031231
and 21 more
#VU105643 - Improper input validation
CVE-2025-1734
CWE-20 Medium
No
No
8.0.30-3.el9_6 12.03.2025 SB2025031234
SB2025031232
SB2025031231
and 21 more
#VU105642 - Improper input validation
CVE-2025-1861
CWE-20 Low
No
No
8.0.30-3.el9_6 12.03.2025 SB2025031234
SB2025031232
SB2025031231
and 21 more
#VU105641 - Improper Authentication
CVE-2025-1736
CWE-287 Medium
No
No
8.0.30-3.el9_6 12.03.2025 SB2025031234
SB2025031232
SB2025031231
and 21 more
#VU105640 - Resource Management Errors
CVE-2025-1219
CWE-399 Low
No
No
8.0.30-3.el9_6 12.03.2025 SB2025031231
SB2025031232
SB2025031233
and 20 more
#VU78978 - Memory corruption
CVE-2023-3824
CWE-119 Critical
Available
Exploited
8.0.30-1.el9_2 06.08.2023 SB2023080604
SB2023081704
SB20230821142
and 32 more
#VU78977 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2023-3823
CWE-611 High
No
No
8.0.30-1.el9_2 06.08.2023 SB2023080604
SB2023081704
SB20230821142
and 31 more
#VU77112 - Use of Insufficiently Random Values
CVE-2023-3247
CWE-330 Medium
No
No
8.0.30-1.el9_2 09.06.2023 SB2023060919
SB2023061105
SB2023061516
and 24 more
#VU72167 - Out-of-bounds write
CVE-2023-0568
CWE-787 Medium
No
No
8.0.30-1.el9_2 14.02.2023 SB2023021417
SB2023021526
SB2023022245
and 27 more
#VU72165 - Improper input validation
CVE-2023-0662
CWE-20 Medium
No
No
8.0.30-1.el9_2 14.02.2023 SB2023021417
SB2023021526
SB2023022245
and 25 more


Showing elements 1 - 20 out of 34