Skip to main content

Threats Tagged 'cve-2025-6491'

View all threats tagged with 'cve-2025-6491'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-6491

Threats Tagged 'cve-2025-6491'

Click on any threat for detailed analysis and mitigation recommendations

0

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server. Security Fix(es): * php: pgsql extension does not check for errors during escaping (CVE-2025-1735) * php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491) * php: PHP Hostname Null Character Vulnerability (CVE-2025-1220) * php: heap-based buffer overflow in array_merge() (CVE-2025-14178) * php: PHP: Information disclosure via getimagesize() function when reading multi-chunk images (CVE-2025-14177) * php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement (CVE-2025-14180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

A vulnerability in the PHP SOAP extension allows a null pointer dereference when parsing XML data with an overly large XML namespace prefix exceeding 2GB. This issue affects PHP versions prior to 8.1.33, 8.2.29, 8.3.23, and 8.4.10. The flaw may cause server crashes, impacting availability.

Join the discussion

A vulnerability in PHP versions 8.1 before 8.1.33, 8.2 before 8.2.29, 8.3 before 8.3.23, and 8.4 before 8.4.10 allows null byte characters in hostnames passed to functions like fsockopen(). This can cause inconsistent hostname parsing by other functions such as parse_url(), potentially leading to security issues if user code relies on these functions for access control. Red Hat has issued security updates addressing this issue.

Join the discussion

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.

Join the discussion

A heap buffer over-read vulnerability exists in the mysqlnd extension of PHP, affecting multiple PHP versions prior to specific fixed releases. A hostile MySQL server can exploit this flaw to cause the PHP client to leak partial heap contents, potentially disclosing data from other SQL requests or other users on the same server. This vulnerability has been assigned CVE-2024-8929 and is rated as having moderate security impact. Official patches are available and have been released by vendors including Red Hat.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2025-6491
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses