296,720
Total vulnerabilities in the database
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
| Software | From | Fixed in |
|---|---|---|
| php / php | 5.5.0 | 5.5.14 |
| php / php | 5.4.0 | 5.4.30 |
| php / php | - | 5.3.29 |
| file_project / file | - | 5.19 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 7.0 | 7.0.x |
| opensuse / opensuse | 11.4 | 11.4.x |
| oracle / linux | 7 | 7.x |