VDB
CVE-2019-11042
CVE-2019-11042
PUBLISHED
EPSS 3.81% · 88.3th percentile
Risk Scores
EPSS Score
3.81%
88.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | php71, php73 | |
| Amazon | php72 |
Exploit Intelligence
- https://bugs.php.net/bug.php?id=78256 (nist-nvd)
- Out of Bounds Memory Read in exif_process_user_comment (hackerone)
- Out of Bounds Memory Read in exif_process_user_comment (hackerone)
- Out of Bounds Memory Read in exif_process_user_comment (hackerone)
- phuip-fpizdam.yara (github-yara)
- phuip-fpizdam.yara (github-yara)
- phuip-fpizdam.yara (github-yara)
- phuip-fpizdam.yara (github-yara)
- phuip-fpizdam.yara (github-yara)
- phuip-fpizdam.yara (github-yara)
…and 1 more exploits
Timeline
- CVE Published
- Nov 9, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Oct 21, 2023 PoC Published
- Mar 17, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 4, 2025 EPSS Score
- Jun 1, 2025 EPSS Score
References
- ALAS-2019-1284: php72 (low) advisory
- ALAS-2019-1283: php71, php73 (low) advisory