<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:50:56 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:7624 — Moderate: php:8.0 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7624</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apcu-panel, AlmaLinux:8: libzip, AlmaLinux:8: libzip-devel, AlmaLinux:8: libzip-tools, AlmaLinux:8: php, AlmaLinux:8: php-bcmath, AlmaLinux:8: php-cli, AlmaLinux:8: php-common, AlmaLinux:8: php-dba, AlmaLinux:8: php-dbg and 25 more&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: php (8.0.20). (BZ#2100876)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* php: Use after free due to php_filter_float() failing for ints (CVE-2021-21708)
* php: Uninitialized array in pg_query_params() leading to RCE (CVE-2022-31625)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: apcu-panel, AlmaLinux:8: libzip, AlmaLinux:8: libzip-devel, AlmaLinux:8: libzip-tools, AlmaLinux:8: php, AlmaLinux:8: php-bcmath, AlmaLinux:8: php-cli, AlmaLinux:8: php-common, AlmaLinux:8: php-dba, AlmaLinux:8: php-dbg and 25 more&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: php (8.0.20). (BZ#2100876)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* php: Use after free due to php_filter_float() failing for ints (CVE-2021-21708)
* php: Uninitialized array in pg_query_params() leading to RCE (CVE-2022-31625)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7624</guid>
    </item>
    <item>
      <title>bdu:2022-05350</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05350</link>
      <description>bdu:2022-05350</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05350</guid>
    </item>
    <item>
      <title>BIT-libphp-2021-21708 — UAF due to php_filter_float() failing</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libphp-2021-21708</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libphp&lt;/p&gt;
&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libphp&lt;/p&gt;
&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libphp-2021-21708</guid>
    </item>
    <item>
      <title>certfr-2022-avi-161 — De multiples vulnérabilités ont été découvertes dans PHP. Elles
permettent à un attaquant de provoquer un problème de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-161</link>
      <description>certfr-2022-avi-161</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-161</guid>
    </item>
    <item>
      <title>EUVD-2026-183555</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183555</link>
      <description>EUVD-2026-183555</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183555</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21708</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21708</link>
      <description>&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21708</guid>
    </item>
    <item>
      <title>FSA-202302 — Festo: Several vulnerabilities in FactoryViews</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202302</link>
      <description>&lt;p&gt;FactoryViews bundles many third-party applications which are used in background processes to provide the software&amp;#39;s features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.&lt;/p&gt;
&lt;p&gt;At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FactoryViews bundles many third-party applications which are used in background processes to provide the software&amp;#39;s features. From time to time, vulnerabilities in these bundled applications are discovered. These are typically fixed in newer versions of FactoryViews by updating the bundled applications.&lt;/p&gt;
&lt;p&gt;FactoryViews versions up to and including 1.5.2 contain around 200 such vulnerabilities listed in this advisory.Version 1.6.0 is a security rollup release which includes updates to all bundled applications and fixes these vulnerabilities.&lt;/p&gt;
&lt;p&gt;At this time, FactoryViews Lite cannot be updated beyond version 1.1. FactoryViews 1.7 unifies the non-Lite and Lite versions and fixes these vulnerabilities for users of FactoryViews Lite.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202302</guid>
    </item>
    <item>
      <title>GHSA-g9qg-rg7j-whhx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9qg-rg7j-whhx</link>
      <description>&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9qg-rg7j-whhx</guid>
    </item>
    <item>
      <title>gsd-2021-21708</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21708</link>
      <description>gsd-2021-21708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21708</guid>
    </item>
    <item>
      <title>ICSA-24-102-04 — Siemens RUGGEDCOM APE1808</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-102-04</link>
      <description>&lt;p&gt;The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script&amp;#39;s use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script&amp;#39;s use of .= with a long string. PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits. NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-102-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-21708 — UAF due to php_filter_float() failing</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-21708</link>
      <description>msrc_CVE-2021-21708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-21708</guid>
    </item>
    <item>
      <title>OESA-2022-1581 — php security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: php, openEuler:20.03-LTS-SP3: php&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.(CVE-2021-21708)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP2: php, openEuler:20.03-LTS-SP3: php&lt;/p&gt;
&lt;p&gt;PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated web pages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module (often referred to as mod_php) which adds support for the PHP language to Apache HTTP Server.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.(CVE-2021-21708)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1581</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0847-1 — Security update for php7</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0847-1</link>
      <description>&lt;p&gt;Security update for php7&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php7&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0847-1</guid>
    </item>
    <item>
      <title>RHSA-2025:3016 — Red Hat Security Advisory: php:7.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:3016</link>
      <description>&lt;p&gt;php: Use after free due to php_filter_float() failing for ints&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: Use after free due to php_filter_float() failing for ints&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:3016</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0654-1 — Security update for php74</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0654-1</link>
      <description>&lt;p&gt;Security update for php74&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for php74&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0654-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-21708</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-21708</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: php7.4, Ubuntu:22.04:LTS: php8.1&lt;/p&gt;
&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: php7.4, Ubuntu:22.04:LTS: php8.1&lt;/p&gt;
&lt;p&gt;In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it crashes, and potentially in overwrite of other memory chunks and RCE. This issue affects: code that uses FILTER_VALIDATE_FLOAT with min/max limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-21708</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0280 — PHP: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0280</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PHP ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PHP ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0280</guid>
    </item>
  </channel>
</rss>
