Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3986-1 | php7.4 security update |
Debian DSA |
DSA-5819-1 | php8.2 security update |
EUVD |
EUVD-2024-33767 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write. |
Ubuntu USN |
USN-7153-1 | PHP vulnerability |
Ubuntu USN |
USN-7157-1 | PHP vulnerabilities |
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 26 Nov 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php
Php php |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Php
Php php |
Tue, 26 Nov 2024 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sun, 24 Nov 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Php Group
Php Group php |
|
| CPEs | cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Php Group
Php Group php |
|
| Metrics |
ssvc
|
Sun, 24 Nov 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write. | |
| Title | Integer overflow in the firebird and dblib quoters causing OOB writes | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-11-03T21:51:54.520Z
Reserved: 2024-11-15T06:27:40.425Z
Link: CVE-2024-11236
Updated: 2025-11-03T21:51:54.520Z
Status : Modified
Published: 2024-11-24T01:15:04.387
Modified: 2025-11-03T22:16:37.600
Link: CVE-2024-11236
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN