php-mbstring vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the php-mbstring package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Input Validation

*
  • M
Information Exposure

*
  • L
Null Byte Interaction Error (Poison Null Byte)

*
  • M
Improper Input Validation

*
  • H
Out-of-Bounds

<0:8.0.30-1.module+el8.8.0+20302+42d2b711
  • H
XML External Entity (XXE) Injection

<0:8.0.30-1.module+el8.8.0+20302+42d2b711
  • H
Unchecked Return Value

<0:8.0.30-1.module+el8.8.0+20302+42d2b711
  • M
Out-of-bounds Write

<0:8.0.27-1.module+el8.7.0+17863+0ad92cd2
  • M
Resource Exhaustion

<0:8.0.30-1.module+el8.8.0+20302+42d2b711
  • M
Allocation of Resources Without Limits or Throttling

<0:8.0.30-1.module+el8.8.0+20302+42d2b711
  • H
Reversible One-Way Hash

<0:8.0.30-1.module+el8.8.0+20302+42d2b711
  • M
Integer Overflow or Wraparound

<0:8.0.27-1.module+el8.7.0+17863+0ad92cd2
  • M
Integer Overflow to Buffer Overflow

<0:8.0.27-1.module+el8.7.0+17863+0ad92cd2
  • M
Improper Input Validation

<0:8.0.27-1.module+el8.7.0+17863+0ad92cd2
  • M
Improper Input Validation

<0:8.0.27-1.module+el8.7.0+17863+0ad92cd2
  • M
Uncontrolled Recursion

<0:8.0.27-1.module+el8.7.0+17863+0ad92cd2
  • H
Buffer Overflow

<0:8.0.13-3.module+el8.6.0+15725+0c79e7c4
  • M
Access of Uninitialized Pointer

<0:8.0.20-2.module+el8.7.0+16187+bb5ab920
  • M
Use After Free

<0:7.4.30-1.module+el8.7.0+15886+8e29b882
  • M
Improper Input Validation

<0:7.4.30-1.module+el8.7.0+15886+8e29b882
  • M
Improper Input Validation

*
  • M
Out-of-Bounds

<0:7.4.19-2.module+el8.6.0+13953+0a59ce9f
  • M
Directory Traversal

<0:7.4.30-1.module+el8.7.0+15886+8e29b882
  • M
Out-of-bounds Write

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Information Exposure

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Information Exposure

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
NULL Pointer Dereference

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-Bounds

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Improper Initialization

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • C
Improper Input Validation

<0:7.2.11-4.module+el8.1.0+4555+f5cb8e18
  • M
NULL Pointer Dereference

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Improper Access Control

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-Bounds

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-Bounds

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Improper Initialization

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Incorrect Privilege Assignment

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Heap-based Buffer Overflow

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Heap-based Buffer Overflow

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Out-of-Bounds

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Uncontrolled Recursion

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Use After Free

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Buffer Overflow

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Integer Overflow or Wraparound

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Buffer Overflow

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Improper Null Termination

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Out-of-bounds Read

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Integer Overflow or Wraparound

<0:7.3.20-1.module+el8.2.0+7373+b272fdef
  • M
Heap-based Buffer Overflow

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Heap-based Buffer Overflow

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Heap-based Buffer Overflow

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Out-of-bounds Read

<0:7.2.24-1.module+el8.2.0+4601+7c76a223
  • M
Improper Input Validation

<0:7.4.19-2.module+el8.6.0+13953+0a59ce9f
  • M
NULL Pointer Dereference

<0:7.4.19-1.module+el8.5.0+11143+cc873159
  • M
Improper Input Validation

<0:7.4.19-1.module+el8.5.0+11143+cc873159
  • M
Improper Input Validation

<0:7.4.19-1.module+el8.5.0+11143+cc873159
  • M
Improper Input Validation

<0:7.4.19-1.module+el8.5.0+11143+cc873159
  • M
Directory Traversal

<0:7.4.19-4.module+el8.6.0+16316+906f6c6d
  • L
Use After Free

*
  • M
Deserialization of Untrusted Data

<0:7.4.19-4.module+el8.6.0+16316+906f6c6d
  • M
Improper Input Validation

<0:7.4.19-4.module+el8.6.0+16316+906f6c6d
  • M
Off-by-one Error

*
  • M
Resource Exhaustion

*
  • M
Improper Input Validation

*