VDB

CVE-2019-9020

CVE-2019-9020 PUBLISHED

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

EPSS 2.39% · 85.4th percentile

Risk Scores

EPSS Score
2.39%
85.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSphp7.20, 7.2.1-1ubuntu2, 7.2.2-1ubuntu1
Ubuntu:14.04:LTSphp5*, 5.5.3+dfsg-1ubuntu3, 5.5.6+dfsg-1ubuntu2
Ubuntu:16.04:LTSphp7.07.0.1-5, 7.0.1-6, 7.0.2-3

Exploit Intelligence

…and 14 more exploits

Timeline

  • CVE Published
  • Nov 9, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • May 1, 2025 EPSS Score
  • May 4, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
  • Jun 4, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›