|
ID# |
Date |
Last Modified |
Package |
Type |
Status |
PHP Version |
OS |
Summary |
Assigned |
35894 (edit) |
2006-01-04 15:40 UTC |
2010-12-01 16:17 UTC |
IMAP related |
Req |
Analyzed |
5.1.2 | Linux |
php-imap doesn't trap USR2 when mailbox is locked |
|
38915 (edit) |
2006-09-21 19:15 UTC |
2014-06-05 09:01 UTC |
Program Execution |
Req |
Analyzed |
5.2.2, 4.4.7 | UNIX |
Apache: system() (and similar) don't cleanup opened handles of Apache |
|
42816 (edit) |
2007-10-01 16:44 UTC |
2021-11-10 16:30 UTC |
Website problem |
Bug |
Analyzed |
Irrelevant | Irrelevant |
[PATCH] Add support for core and magic constants to error.php |
|
46451 (edit) |
2008-11-01 14:19 UTC |
2020-11-16 16:24 UTC |
Session related |
Req |
Analyzed |
* | * |
Session module needs a hook into the evaluator |
|
49106 (edit) |
2009-07-30 02:40 UTC |
2021-10-27 09:18 UTC |
Apache2 related |
Bug |
Analyzed |
5.*, 6 | * |
PHP incorrectly sets no_local_copy=1 on response as Apache 2 module |
|
54051 (edit) |
2011-02-18 22:28 UTC |
2021-10-12 12:50 UTC |
PHP options/info functions |
Bug |
Analyzed |
Irrelevant | Debian GNU/Linux |
output_buffering boolean values not interpreted correctly |
|
55820 (edit) |
2011-09-30 15:45 UTC |
2021-12-18 21:19 UTC |
OpenSSL related |
Req |
Analyzed |
5.3.8 | Ubuntu Linux 10.04 |
php openssl csr parser ignores SANs |
|
60224 (edit) |
2011-11-05 13:50 UTC |
2021-07-13 14:05 UTC |
Doc Build problem |
Bug |
Analyzed |
Irrelevant | |
div nesting in html docs |
|
60412 (edit) |
2011-11-29 22:17 UTC |
2015-01-08 22:11 UTC |
mbstring related |
Req |
Analyzed |
5.4SVN-2011-11-04 (SVN) | all |
UTF-8 functions doesn't respect unicode equivalence - Need Normalization |
|
61972 (edit) |
2012-05-07 21:09 UTC |
2018-08-07 15:20 UTC |
SimpleXML related |
Doc |
Analyzed |
5.4.2 | Windows XP |
addchild treats text as a tag |
|
63343 (edit) |
2012-10-24 00:06 UTC |
2021-06-14 09:03 UTC |
PDO related |
Bug |
Analyzed |
Irrelevant | Mixed |
Commit failure for repeated persistent connection |
|
63501 (edit) |
2012-11-13 12:00 UTC |
2015-12-30 17:12 UTC |
gmagick |
Bug |
Analyzed |
5.4.8 | Linux (CentOS) |
Setfillopacity causes a box around each letter |
|
63709 (edit) |
2012-12-06 13:12 UTC |
2013-04-04 08:32 UTC |
Filesystem function related |
Bug |
Analyzed |
5.3.19 | Linux |
flock() doesn't trigger mandatory locks on linux |
|
64312 (edit) |
2013-02-27 15:43 UTC |
2021-09-01 12:31 UTC |
*General Issues |
Doc |
Analyzed |
5.4.12 | Win7 32 bits |
set_error_handler always return handler if called inside an error_handler |
|
64447 (edit) |
2013-03-18 19:09 UTC |
2018-04-29 11:15 UTC |
Doc Build problem |
Bug |
Analyzed |
Irrelevant | |
Syntax highlighting is old |
|
65014 (edit) |
2013-06-11 15:50 UTC |
2020-12-07 16:46 UTC |
Scripting Engine problem |
Bug |
Analyzed |
5.6.11 | * |
namespaced class not found after including it in an error handler |
|
65343 (edit) |
2013-07-26 13:34 UTC |
2021-08-30 14:37 UTC |
Network related |
Req |
Analyzed |
5.5.1 | any |
Not all DNS types supported in dns_get_record |
|
65455 (edit) |
2013-08-15 11:25 UTC |
2020-11-17 12:49 UTC |
IMAP related |
Bug |
Analyzed |
5.4.17 | |
in Unknown on line 0 |
|
65500 (edit) |
2013-08-22 08:30 UTC |
2021-08-31 13:43 UTC |
FPM related |
Bug |
Analyzed |
5.4 or later | any |
debug_backtrace doesn't identify file name when config contains invalid comment |
|
65987 (edit) |
2013-10-29 00:42 UTC |
2020-05-13 13:48 UTC |
*Extensibility Functions |
Bug |
Analyzed |
Irrelevant | Windows |
memory leak and handle leak in shmop |
|
66174 (edit) |
2013-11-26 12:59 UTC |
2021-02-18 15:19 UTC |
FTP related |
Bug |
Analyzed |
master-Git-2013-11-26 (Git) | all |
Interruption vulnerability in ftp_nb_fget() |
|
66232 (edit) |
2013-12-04 05:14 UTC |
2022-12-27 17:35 UTC |
Streams related |
Bug |
Analyzed |
5.5Git-2013-12-04 (Git) | Linux 3.11.4-vhost-blk+ x86_64 |
proc_open: Inconsistent handling of EOFs on pipes |
bukka |
70379 (edit) |
2015-08-28 09:00 UTC |
2015-08-30 13:54 UTC |
Unknown/Other Function |
Doc |
Analyzed |
7.0.0RC1 | OSX |
call_user_func_array only accepts explicit references |
|
71101 (edit) |
2015-12-12 13:09 UTC |
2021-09-24 14:09 UTC |
Session related |
Doc |
Analyzed |
Irrelevant | * |
serialize_handler must not be switched for existing sessions |
|
71340 (edit) |
2016-01-11 18:24 UTC |
2018-06-18 07:22 UTC |
PHP options/info functions |
Doc |
Analyzed |
7.0 | Any |
php_admin_value[error_reporting] in fpm/apache conf can be bypassed in user code |
|
71506 (edit) |
2016-02-03 10:54 UTC |
2016-08-02 15:18 UTC |
Zlib related |
Bug |
Analyzed |
Irrelevant | Slackware 14.1 |
inflate_add() does not detect truncated data |
|
71607 (edit) |
2016-02-16 07:51 UTC |
2016-02-18 14:00 UTC |
Apache2 related |
Doc |
Analyzed |
5.6.18 | Windows 8.1 |
putenv/getenv parameters are passed to subrequests |
|
72247 (edit) |
2016-05-20 02:46 UTC |
2019-09-19 01:55 UTC |
OpenSSL related |
Req |
Analyzed |
master-Git-2016-05-20 (Git) | Windows10/CentOS7.2 |
There is no way to get key length for cipher algorithms |
|
75554 (edit) |
2017-11-22 12:37 UTC |
2020-03-25 15:48 UTC |
Apache2 related |
Bug |
Analyzed |
7.1.11 | Linux Mint 18, Ubuntu 12.04 LTS |
session_regenerate_id() causes duplicate Set-Cookie header to be sent |
|
75584 (edit) |
2017-11-28 01:11 UTC |
2022-12-28 17:42 UTC |
Streams related |
Bug |
Analyzed |
7.1.12 | Arch Linux=Y Windows=? macOS=? |
Docs?: stream_select() ignores proc_open() streams for buffered fopen() streams |
bukka |
76232 (edit) |
2018-04-18 08:31 UTC |
2018-04-19 18:55 UTC |
SOAP related |
Bug |
Analyzed |
7.0.29 | Ubuntu 16.04.4 |
SoapClient Cookie Header Semicolon |
|
76268 (edit) |
2018-04-25 14:35 UTC |
2020-06-17 16:25 UTC |
cURL related |
Bug |
Analyzed |
7.1.16 | linux, debian 10 x64 k4.15.11-1 |
stream_get_contents fail to seek on streams modified by curl_exec |
|
77229 (edit) |
2018-12-03 02:54 UTC |
2020-11-26 13:28 UTC |
PHAR related |
Bug |
Analyzed |
7.4 | macOS High Sierra 10.13.6 |
Phar::buildFromDirectory() generates tar archives in 'PAX' format |
|
77977 (edit) |
2019-05-06 18:50 UTC |
2020-02-24 09:04 UTC |
SQLite related |
Bug |
Analyzed |
7.3.5 | Linux |
heap use-after-free via UDF in sqlite |
|
78596 (edit) |
2019-09-25 14:23 UTC |
2019-09-25 15:48 UTC |
PDO MySQL |
Bug |
Analyzed |
7.2.22 | linux |
getColumnMeta() doesn't return native_type for JSON |
|
79209 (edit) |
2020-02-01 18:56 UTC |
2020-02-04 14:02 UTC |
Scripting Engine problem |
Bug |
Analyzed |
master-Git-2020-02-01 (Git) | ALL |
Free a potentially controllable pointer in zend_hash_packed_to_hash |
|
79350 (edit) |
2020-03-07 04:12 UTC |
2021-07-23 09:29 UTC |
Scripting Engine problem |
Bug |
Analyzed |
master-Git-2020-03-07 (Git) | Linux |
Classes with __toString() do not support early binding |
|
80201 (edit) |
2020-10-07 18:41 UTC |
2020-10-19 08:09 UTC |
IMAP related |
Bug |
Analyzed |
7.4.11 | linux/windows |
incomplete header returned |
|
80246 (edit) |
2020-10-16 15:28 UTC |
2021-12-14 14:14 UTC |
Scripting Engine problem |
Bug |
Analyzed |
7.4.11 | 18.04.4 LTS |
SEGV in zend_fetch_dimension_address_read() |
|
80344 (edit) |
2020-11-09 15:39 UTC |
2020-11-09 15:39 UTC |
MySQL related |
Req |
Analyzed |
7.4.12 | any |
mysqlnd support for SASL SCRAM-SHA-1 and SCRAM-SHA-256 authentication |
fjanisze |
81027 (edit) |
2021-05-10 14:04 UTC |
2021-08-12 10:52 UTC |
Unknown/Other Function |
Bug |
Analyzed |
8.0.6 | Linux |
WeakReference will cause memory leaks |
|
33781 (edit) |
2005-07-20 09:40 UTC |
2022-12-27 18:10 UTC |
Streams related |
Req |
Assigned |
* | * |
add "stream_set_timeout" support for pipes |
bukka |
41241 (edit) |
2007-04-30 13:01 UTC |
2017-10-24 03:05 UTC |
PostgreSQL related |
Req |
Assigned |
* | * |
Realization array type. SQL 2003, S091 |
yohgaki |
52322 (edit) |
2010-07-12 23:03 UTC |
2020-06-25 08:44 UTC |
PHAR related |
Bug |
Assigned |
5.2.13 | * |
webPhar acting like not running in webpage |
bishop |
53926 (edit) |
2011-02-04 18:47 UTC |
2017-10-24 09:12 UTC |
SPL related |
Doc |
Assigned |
Irrelevant | Irrelevant |
LimitIterator::rewind() problem |
salathe |
58954 (edit) |
2009-11-17 23:08 UTC |
2020-01-26 01:02 UTC |
uploadprogress |
Req |
Assigned |
5.2.6 | Windows XP |
Status of completed files |
ramsey |
59307 (edit) |
2010-07-14 11:29 UTC |
2020-01-26 01:05 UTC |
uploadprogress |
Bug |
Assigned |
5.2.10 | Ubuntu Server 9.10 |
The call uploadprogress_get_info(hash) sometimes returns nothing |
ramsey |
59721 (edit) |
2011-04-19 05:33 UTC |
2020-01-26 01:05 UTC |
uploadprogress |
Bug |
Assigned |
5.2.15 | Windows |
Can't define uploadprogress.file.filename_template on another drive |
ramsey |
59918 (edit) |
2011-08-31 04:09 UTC |
2021-04-30 16:18 UTC |
uploadprogress |
Req |
Assigned |
5.3.6 | CentOS 5.2 |
Progress for uploads > 2GB breaks (32bit issue?) |
ramsey |
60110 (edit) |
2011-10-21 19:38 UTC |
2023-08-29 15:41 UTC |
Streams related |
Bug |
Assigned |
5.3.8 | all |
fclose(), file_put_contents(), copy() do not return false properly |
bukka |
60187 (edit) |
2011-11-01 10:47 UTC |
2015-02-03 06:51 UTC |
PostgreSQL related |
Req |
Assigned |
5.3.8 | SuSE Linux 11 SP1 |
pgsql module returns strings from SELECT queries for each unempty field |
yohgaki |
60961 (edit) |
2012-02-02 20:25 UTC |
2021-12-09 22:15 UTC |
FPM related |
Bug |
Assigned |
7.0 | Debian Squeeze |
Graceful Restart (USR2) isn't very graceful |
bukka |
62065 (edit) |
2012-05-18 20:26 UTC |
2017-10-24 03:25 UTC |
PDO related |
Req |
Assigned |
5.3.13 | Any |
PDO should have a disconnect method |
willfitch |
62106 (edit) |
2012-05-22 07:47 UTC |
2016-09-05 15:39 UTC |
Zip Related |
Bug |
Assigned |
master-Git-2012-05-22 (Git) | Unix/POSIX, maybe Windows |
zip can (and will, in real-life cases) leak huge tempfiles |
ab |
62630 (edit) |
2012-07-21 11:20 UTC |
2021-12-11 21:15 UTC |
FPM related |
Req |
Assigned |
5.4.5 | |
issues with starting FPM in conditions of high load |
bukka |
62906 (edit) |
2012-08-23 15:02 UTC |
2022-02-13 04:35 UTC |
cURL related |
Req |
Assigned |
Irrelevant | All |
[feature request] add support for CURLOPT_*SOCK* options |
laruence |
63314 (edit) |
2012-10-19 18:17 UTC |
2017-10-24 03:24 UTC |
Bitset |
Bug |
Assigned |
Irrelevant | Linux |
Bitset needs serialization handler |
willfitch |
63765 (edit) |
2012-12-14 00:22 UTC |
2017-10-24 05:06 UTC |
rar |
Bug |
Assigned |
5.4.9 | Gentoo |
unrar should be unbundled |
cataphract |
63767 (edit) |
2012-12-14 08:33 UTC |
2017-10-24 05:01 UTC |
FTP related |
Bug |
Assigned |
5.4.9 | Windows |
Follow up for Bug #36103 |
kaplan |
63771 (edit) |
2012-12-14 19:56 UTC |
2021-08-23 16:15 UTC |
Bitset |
Req |
Assigned |
Irrelevant | |
Implement SPL interfaces on Bitsets |
willfitch |
63888 (edit) |
2013-01-02 20:44 UTC |
2022-03-28 18:35 UTC |
FPM related |
Doc |
Assigned |
Irrelevant | |
Missing several PHP FPM ini entries in online documentation |
bukka |
64008 (edit) |
2013-01-16 16:55 UTC |
2016-02-07 15:43 UTC |
PDO_INFORMIX |
Bug |
Assigned |
5.4.10 | OpenSuse 12.2 |
PDO Informix returns corrupted strings when character conversion is active |
vnkbabu |
65109 (edit) |
2013-06-24 10:02 UTC |
2020-11-03 18:01 UTC |
Doc Build problem |
Bug |
Assigned |
Irrelevant | Windows 7 |
Extraneous empty paragraphs in generated HTML |
salathe |
65746 (edit) |
2013-09-23 22:41 UTC |
2018-06-02 08:49 UTC |
Session related |
Req |
Assigned |
Any | Any |
session_regenerate_id() should not delete old session data immediately. |
yohgaki |
66368 (edit) |
2013-12-30 08:30 UTC |
2022-02-13 03:01 UTC |
*General Issues |
Req |
Assigned |
Irrelevant | Irrelevant |
Operators should also be functions |
ajf |
66710 (edit) |
2014-02-13 19:02 UTC |
2016-12-08 09:43 UTC |
Doc Build problem |
Bug |
Assigned |
5.5.9 | Windows |
using phd.config.php but not set all config will error |
sobak |
66724 (edit) |
2014-02-16 19:10 UTC |
2017-01-22 15:22 UTC |
LDAP related |
Bug |
Assigned |
5.4.25 | Debian Linux |
ldap_get_entries does not escape DN values on Active Directory |
heiglandreas |
67141 (edit) |
2014-04-28 10:45 UTC |
2023-09-17 15:50 UTC |
FPM related |
Bug |
Assigned |
5.5.11 | ubuntu 14.04 |
PHP FPM vhost pollution |
bukka |
67379 (edit) |
2014-06-04 08:08 UTC |
2017-10-24 09:21 UTC |
Documentation problem |
Doc |
Assigned |
Irrelevant | |
Not all implemented methods documented for some iterators |
salathe |
67401 (edit) |
2014-06-09 07:53 UTC |
2017-10-24 09:22 UTC |
Website problem |
Bug |
Assigned |
Irrelevant | |
people.php.net doesn't fetch notes |
salathe |
67897 (edit) |
2014-08-24 06:45 UTC |
2016-07-14 11:17 UTC |
Scripting Engine problem |
Bug |
Assigned |
Irrelevant | |
Closure definition affects output with relative constants |
dmitry |
68019 (edit) |
2014-09-13 23:37 UTC |
2021-12-04 18:19 UTC |
FPM related |
Req |
Assigned |
Irrelevant | |
FPM INI settings from Env |
bukka |
68050 (edit) |
2014-09-19 09:25 UTC |
2017-02-24 09:22 UTC |
PDO_IBM |
Bug |
Assigned |
5.4.33 | SUSE SERVER ENTERPRISE 12.2 |
Multibytes Chars |
vnkbabu |
68219 (edit) |
2014-10-13 18:14 UTC |
2023-10-14 22:52 UTC |
Output Control |
Req |
Assigned |
5.5.17 | ANY |
Make http_response_code() also returns the text of response |
bukka |
68366 (edit) |
2014-11-06 16:24 UTC |
2021-12-17 11:32 UTC |
OpenSSL related |
Req |
Assigned |
5.4.34 | All |
Does not use certificate's signing algorithm |
bukka |
68534 (edit) |
2014-12-01 17:23 UTC |
2017-01-28 12:48 UTC |
OCI8 related |
Doc |
Assigned |
Irrelevant | |
Ambiguity about oci_close and persistent connection |
sixd |
68537 (edit) |
2014-12-02 08:32 UTC |
2017-01-28 12:48 UTC |
OCI8 related |
Doc |
Assigned |
5.4.35 | Gentoo GNU/Linux |
oci_bind_by_name() should provide unity length description |
sixd |
68599 (edit) |
2014-12-12 23:02 UTC |
2020-01-27 14:01 UTC |
Program Execution |
Req |
Assigned |
Irrelevant | ANY |
exec()/passthru() function should use execv, execve |
yohgaki |
68824 (edit) |
2015-01-13 11:29 UTC |
2021-12-04 21:12 UTC |
FPM related |
Req |
Assigned |
5.6.4 | linux |
php-rpm pm=static causes load peaks when pm.max_requests is reached |
bukka |
68926 (edit) |
2015-01-27 21:38 UTC |
2017-10-24 05:46 UTC |
*Directory/Filesystem functions |
Bug |
Assigned |
5.6Git-2015-01-27 (Git) | Windows 8 64b Prof. |
is_writable returns false but file_put_contents works |
ab |
69127 (edit) |
2015-02-26 18:05 UTC |
2021-09-28 14:29 UTC |
Session related |
Bug |
Assigned |
Any | Any |
session_regenerate_id(true) randomly generates a warning and loses session data |
yohgaki |
69261 (edit) |
2015-03-19 09:47 UTC |
2017-01-28 17:17 UTC |
SPL related |
Doc |
Assigned |
5.5.22 | Fedora 20 |
getPathname() returns path based on what's passed to the iterator |
salathe |
69394 (edit) |
2015-04-07 13:19 UTC |
2016-08-27 06:40 UTC |
Session related |
Req |
Assigned |
any | any |
SessionHandler should not used previously defined save handler as its base class |
yohgaki |
69407 (edit) |
2015-04-09 09:12 UTC |
2018-08-11 12:52 UTC |
Class/Object related |
Doc |
Assigned |
Irrelevant | |
Better describe object-to-object comparison |
salathe |
69447 (edit) |
2015-04-14 14:53 UTC |
2015-04-14 14:53 UTC |
Scripting Engine problem |
Bug |
Assigned |
5.5.23 | |
Return-by-ref / yield-by-ref confusion in LSP checks |
nikic |
69890 (edit) |
2015-06-20 13:39 UTC |
2021-12-04 18:33 UTC |
FPM related |
Req |
Assigned |
7.0.0alpha1 | Debian 8.1 x64 |
pm.ondemand does not kill children after reaching max limit |
bukka |
69966 (edit) |
2015-06-30 08:18 UTC |
2015-06-30 08:41 UTC |
Documentation problem |
Doc |
Assigned |
Irrelevant | Irrelevant |
Documentation on bucket brigades missing |
salathe |
70024 (edit) |
2015-07-08 14:47 UTC |
2019-03-15 15:42 UTC |
*Compile Issues |
Req |
Assigned |
7.0.0alpha2 | |
Add column information to AST |
nikic |
70134 (edit) |
2015-07-24 20:41 UTC |
2021-12-04 18:22 UTC |
FPM related |
Req |
Assigned |
5.5.27 | Ubuntu |
open_basedir bypass with IP-based PHP-FPM |
bukka |
70210 (edit) |
2015-08-07 23:31 UTC |
2015-08-08 06:32 UTC |
*Compile Issues |
Bug |
Assigned |
7.0.0beta3 | |
Parser: some ASTs may get wrong line numbers |
nikic |
|