Skip to main content

CVE-2022-31627

7.7
HIGHCVSS v3.1 Base Score
0.31%
LOW RiskEPSS (54th percentile)

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

Published: 7/28/2022
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS Score (Exploitation Probability)

0.31%LOW Exploitation Risk
54th percentile

This vulnerability has a 0.31% probability of being exploited in the next 30 days, ranking higher than 54% of all scored CVEs.

CWE Classification

Related Vulnerabilities