Skip to main content

Threats Tagged 'cve-2025-1219'

View all threats tagged with 'cve-2025-1219'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-1219

Threats Tagged 'cve-2025-1219'

Click on any threat for detailed analysis and mitigation recommendations

0

Multiple security vulnerabilities have been identified and addressed in PHP as packaged by Red Hat Enterprise Linux 10. These include issues in the HTTP stream wrapper related to header parsing, authentication header omission, invalid header handling, content-type header misuse on redirects, and redirect location truncation. Additionally, a use-after-free vulnerability exists in the PHP request shutdown process. Red Hat has released updates to fix these issues in their PHP packages for various architectures and support levels.

Join the discussion

A vulnerability in PHP's HTTP stream wrapper header parser affects versions prior to 8.1.32, 8.2.28, 8.3.19, and 8.4.5. The parser incorrectly handles folded HTTP headers, which can lead to misinterpretation of HTTP responses, including incorrect headers and MIME types. This issue has been rated as moderate severity by Red Hat Product Security. A patch is available to address this vulnerability.

Join the discussion

A use-after-free vulnerability exists in PHP versions 8.3 prior to 8.3.19 and 8.4 prior to 8.4.5 involving reference counting during php_request_shutdown. This flaw can be triggered by specific code sequences using the __set handler or the ??= operator combined with exceptions. Exploitation requires control over memory layout, potentially allowing remote code execution. Red Hat has issued security updates addressing this vulnerability.

Join the discussion

A heap buffer over-read vulnerability exists in the mysqlnd extension of PHP, affecting multiple PHP versions prior to specific fixed releases. A hostile MySQL server can exploit this flaw to cause the PHP client to leak partial heap contents, potentially disclosing data from other SQL requests or other users on the same server. This vulnerability has been assigned CVE-2024-8929 and is rated as having moderate security impact. Official patches are available and have been released by vendors including Red Hat.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2025-1219
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses