Threats Tagged 'cve-2025-6491'
View all threats tagged with 'cve-2025-6491'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-6491'
Click on any threat for detailed analysis and mitigation recommendations
0 PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: pgsql extension does not check for errors during escaping (CVE-2025-1735) * php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491) * php: PHP Hostname Null Character Vulnerability (CVE-2025-1220) * php: heap-based buffer overflow in array_merge() (CVE-2025-14178) * php: PHP: Information disclosure via getimagesize() function when reading multi-chunk images (CVE-2025-14177) * php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement (CVE-2025-14180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 01/27/2026, 18:07:34 UTC Added: 06/06/2026, 21:13:28 UTC |
0 A vulnerability in the PHP SOAP extension allows a null pointer dereference when parsing XML data with an overly large XML namespace prefix exceeding 2GB. This issue affects PHP versions prior to 8.1.33, 8.2.29, 8.3.23, and 8.4.10. The flaw may cause server crashes, impacting availability. Join the discussion | GCVE Database | 07/16/2025, 08:19:30 UTC Added: 09/08/2026, 12:55:56 UTC |
0 A vulnerability in PHP versions 8.1 before 8.1.33, 8.2 before 8.2.29, 8.3 before 8.3.23, and 8.4 before 8.4.10 allows null byte characters in hostnames passed to functions like fsockopen(). This can cause inconsistent hostname parsing by other functions such as parse_url(), potentially leading to security issues if user code relies on these functions for access control. Red Hat has issued security updates addressing this issue. Join the discussion | GCVE Database | 07/16/2025, 08:19:12 UTC Added: 06/06/2026, 21:13:28 UTC |
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server. Join the discussion | CVE Database V5 | 07/13/2025, 22:10:15 UTC Added: 07/13/2025, 22:16:03 UTC |
0 A heap buffer over-read vulnerability exists in the mysqlnd extension of PHP, affecting multiple PHP versions prior to specific fixed releases. A hostile MySQL server can exploit this flaw to cause the PHP client to leak partial heap contents, potentially disclosing data from other SQL requests or other users on the same server. This vulnerability has been assigned CVE-2024-8929 and is rated as having moderate security impact. Official patches are available and have been released by vendors including Red Hat. Join the discussion | GCVE Database | 11/27/2024, 19:18:36 UTC Added: 06/06/2026, 21:13:28 UTC |
Showing 1 to 5 of 5 results