Threats Tagged 'cve-2024-11235'
View all threats tagged with 'cve-2024-11235'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-11235'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities have been identified and addressed in PHP as packaged by Red Hat Enterprise Linux 10. These include issues in the HTTP stream wrapper related to header parsing, authentication header omission, invalid header handling, content-type header misuse on redirects, and redirect location truncation. Additionally, a use-after-free vulnerability exists in the PHP request shutdown process. Red Hat has released updates to fix these issues in their PHP packages for various architectures and support levels. Join the discussion | GCVE Database | 05/13/2025, 17:18:22 UTC Added: 06/27/2026, 22:08:41 UTC |
A use-after-free vulnerability exists in PHP versions 8.3 prior to 8.3.19 and 8.4 prior to 8.4.5 involving reference counting during php_request_shutdown. This flaw can be triggered by specific code sequences using the __set handler or the ??= operator combined with exceptions. Exploitation requires control over memory layout, potentially allowing remote code execution. Red Hat has issued security updates addressing this vulnerability. Join the discussion | GCVE Database | 04/14/2025, 11:38:04 UTC Added: 06/27/2026, 22:08:41 UTC |
0 In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution. Join the discussion | CVE Database V5 | 04/04/2025, 17:51:07 UTC Added: 02/26/2026, 19:40:40 UTC |
Showing 1 to 3 of 3 results