[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2019-11040":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":23,"aliases":33,"duplicate_of":9,"upstream":34,"downstream":35,"duplicates":72,"related":73,"reserved_at":9,"published_at":82,"modified_at":83,"state":84,"summary":85,"references_raw":93,"kevs":135,"epss":136,"epss_history":139,"metrics":399,"affected":417},"CVE-2019-11040","When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-125","Out-of-bounds Read","The product reads data past the end, or before the beginning, of the intended buffer.","weakness","Draft","Base",[19],{"id":20,"name":21,"techniques":22},"CAPEC-540","Overread Buffers",[],[24],{"_key":25,"name":26,"source":27,"url":28,"maturity":29,"reliability_score":30,"verified":31,"type":9,"platforms":32,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_EB13A48A5A1126E3","Exploit Reference (bugs.php.net)","reference","https://bugs.php.net/bug.php?id=77988","unknown",0.2,false,[],[],[],[36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70],{"_key":37},"SUSE-SU-2019:1724-1",{"_key":39},"SUSE-SU-2019:1725-1",{"_key":41},"SUSE-SU-2019:1746-1",{"_key":43},"SUSE-SU-2019:1832-1",{"_key":45},"SUSE-SU-2022:4067-1",{"_key":47},"OPENSUSE-SU-2019:1778-1",{"_key":49},"OPENSUSE-SU-2024:11167-1",{"_key":51},"OPENSUSE-SU-2024:11169-1",{"_key":53},"RHSA-2020:1624",{"_key":55},"DLA-1813-1",{"_key":57},"DSA-4527-1",{"_key":59},"DSA-4529-1",{"_key":61},"UBUNTU-CVE-2019-11040",{"_key":63},"USN-4009-1",{"_key":65},"USN-4009-2",{"_key":67},"RHSA-2019:2519",{"_key":69},"RHSA-2019:3299",{"_key":71},"RHSA-2020:3662",[],[74,75,76,77,78,79,80,81],{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},"2019-06-18T23:28:28.320Z","2024-09-16T17:23:01.910Z","Modified",{"cisa_kev":31,"cisa_ransomware":31,"cisa_vendor":9,"epss_severity":86,"epss_score":87,"severity":88,"severity_score":89,"severity_version":90,"severity_source":91,"severity_vector":92,"severity_status":84},"low",0.01215,"critical",9.1,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",[94,102,108,113,118,123,127,131],{"url":28,"sources":95,"tags":97},[96,91],"cve.org",[98,99,100,101],"X Refsource CONFIRM","Exploit","Mailing List","Vendor Advisory",{"url":103,"sources":104,"tags":105},"http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00029.html",[96,91],[101,106,100,107],"X Refsource SUSE","Third Party Advisory",{"url":109,"sources":110,"tags":111},"https://access.redhat.com/errata/RHSA-2019:2519",[96,91],[101,112,107],"X Refsource REDHAT",{"url":114,"sources":115,"tags":116},"https://seclists.org/bugtraq/2019/Sep/35",[96,91],[100,117,107],"X Refsource BUGTRAQ",{"url":119,"sources":120,"tags":121},"https://www.debian.org/security/2019/dsa-4527",[96,91],[101,122,107],"X Refsource DEBIAN",{"url":124,"sources":125,"tags":126},"https://www.debian.org/security/2019/dsa-4529",[96,91],[101,122,107],{"url":128,"sources":129,"tags":130},"https://seclists.org/bugtraq/2019/Sep/38",[96,91],[100,117,107],{"url":132,"sources":133,"tags":134},"https://access.redhat.com/errata/RHSA-2019:3299",[96,91],[101,112,107],[],{"date":137,"score":87,"percentile":138},"2026-06-04",0.79346,[140,144,147,150,153,156,158,161,164,167,170,173,176,178,180,184,187,190,193,195,198,201,204,207,210,212,214,217,221,224,226,229,232,235,237,240,243,247,250,253,256,259,262,265,268,271,274,277,280,283,285,287,290,293,297,300,303,305,308,312,315,317,320,323,326,329,332,335,338,341,343,346,349,351,354,357,360,363,365,368,371,374,377,380,383,386,389,392,394,396],{"date":141,"score":142,"percentile":143},"2025-11-04",0.01044,0.76778,{"date":145,"score":142,"percentile":146},"2025-11-05",0.76777,{"date":148,"score":142,"percentile":149},"2025-11-06",0.76774,{"date":151,"score":142,"percentile":152},"2025-11-07",0.76788,{"date":154,"score":142,"percentile":155},"2025-11-08",0.76792,{"date":157,"score":142,"percentile":152},"2025-11-09",{"date":159,"score":142,"percentile":160},"2025-11-10",0.76772,{"date":162,"score":142,"percentile":163},"2025-11-11",0.76775,{"date":165,"score":142,"percentile":166},"2025-11-12",0.76793,{"date":168,"score":142,"percentile":169},"2025-11-13",0.76801,{"date":171,"score":142,"percentile":172},"2025-11-14",0.76808,{"date":174,"score":142,"percentile":175},"2025-11-15",0.76803,{"date":177,"score":142,"percentile":169},"2025-11-16",{"date":179,"score":142,"percentile":155},"2025-11-17",{"date":181,"score":182,"percentile":183},"2025-11-18",0.02098,0.82656,{"date":185,"score":182,"percentile":186},"2025-11-19",0.82655,{"date":188,"score":182,"percentile":189},"2025-11-20",0.82658,{"date":191,"score":142,"percentile":192},"2025-11-21",0.76818,{"date":194,"score":142,"percentile":192},"2025-11-22",{"date":196,"score":142,"percentile":197},"2025-11-23",0.76804,{"date":199,"score":142,"percentile":200},"2025-11-24",0.76805,{"date":202,"score":142,"percentile":203},"2025-11-25",0.76811,{"date":205,"score":142,"percentile":206},"2025-11-26",0.76817,{"date":208,"score":142,"percentile":209},"2025-11-27",0.76819,{"date":211,"score":142,"percentile":172},"2025-11-28",{"date":213,"score":142,"percentile":206},"2025-11-29",{"date":215,"score":142,"percentile":216},"2025-11-30",0.76814,{"date":218,"score":219,"percentile":220},"2025-12-01",0.00752,0.72482,{"date":222,"score":219,"percentile":223},"2025-12-02",0.72493,{"date":225,"score":219,"percentile":223},"2025-12-03",{"date":227,"score":142,"percentile":228},"2025-12-04",0.76812,{"date":230,"score":142,"percentile":231},"2025-12-05",0.7682,{"date":233,"score":142,"percentile":234},"2025-12-06",0.76823,{"date":236,"score":142,"percentile":209},"2025-12-07",{"date":238,"score":142,"percentile":239},"2025-12-08",0.76824,{"date":241,"score":142,"percentile":242},"2025-12-09",0.76851,{"date":244,"score":245,"percentile":246},"2025-12-10",0.01239,0.78679,{"date":248,"score":245,"percentile":249},"2025-12-11",0.78694,{"date":251,"score":245,"percentile":252},"2025-12-12",0.78716,{"date":254,"score":245,"percentile":255},"2025-12-13",0.78717,{"date":257,"score":245,"percentile":258},"2025-12-14",0.78715,{"date":260,"score":245,"percentile":261},"2025-12-15",0.78714,{"date":263,"score":245,"percentile":264},"2025-12-16",0.78725,{"date":266,"score":245,"percentile":267},"2025-12-17",0.78733,{"date":269,"score":245,"percentile":270},"2025-12-18",0.78751,{"date":272,"score":245,"percentile":273},"2025-12-19",0.78763,{"date":275,"score":245,"percentile":276},"2025-12-20",0.78759,{"date":278,"score":245,"percentile":279},"2025-12-21",0.7875,{"date":281,"score":245,"percentile":282},"2025-12-22",0.78752,{"date":284,"score":245,"percentile":270},"2025-12-23",{"date":286,"score":245,"percentile":273},"2025-12-24",{"date":288,"score":245,"percentile":289},"2025-12-25",0.78783,{"date":291,"score":245,"percentile":292},"2025-12-26",0.7878,{"date":294,"score":295,"percentile":296},"2025-12-27",0.01623,0.81442,{"date":298,"score":245,"percentile":299},"2025-12-28",0.7877,{"date":301,"score":245,"percentile":302},"2025-12-29",0.78764,{"date":304,"score":245,"percentile":299},"2025-12-30",{"date":306,"score":245,"percentile":307},"2025-12-31",0.78785,{"date":309,"score":310,"percentile":311},"2026-01-01",0.00894,0.75182,{"date":313,"score":310,"percentile":314},"2026-01-02",0.75185,{"date":316,"score":310,"percentile":314},"2026-01-03",{"date":318,"score":245,"percentile":319},"2026-01-04",0.78778,{"date":321,"score":245,"percentile":322},"2026-01-05",0.78774,{"date":324,"score":245,"percentile":325},"2026-01-06",0.78781,{"date":327,"score":245,"percentile":328},"2026-01-07",0.78788,{"date":330,"score":245,"percentile":331},"2026-01-08",0.78796,{"date":333,"score":245,"percentile":334},"2026-01-09",0.78798,{"date":336,"score":245,"percentile":337},"2026-01-10",0.78801,{"date":339,"score":245,"percentile":340},"2026-01-11",0.78794,{"date":342,"score":245,"percentile":289},"2026-01-12",{"date":344,"score":245,"percentile":345},"2026-01-13",0.78779,{"date":347,"score":245,"percentile":348},"2026-01-14",0.78799,{"date":350,"score":245,"percentile":337},"2026-01-15",{"date":352,"score":245,"percentile":353},"2026-01-16",0.78807,{"date":355,"score":245,"percentile":356},"2026-01-17",0.78814,{"date":358,"score":245,"percentile":359},"2026-01-18",0.78811,{"date":361,"score":245,"percentile":362},"2026-01-19",0.78808,{"date":364,"score":245,"percentile":353},"2026-01-20",{"date":366,"score":245,"percentile":367},"2026-01-21",0.78813,{"date":369,"score":245,"percentile":370},"2026-01-22",0.78821,{"date":372,"score":245,"percentile":373},"2026-01-23",0.78849,{"date":375,"score":245,"percentile":376},"2026-01-24",0.7886,{"date":378,"score":245,"percentile":379},"2026-01-25",0.78854,{"date":381,"score":245,"percentile":382},"2026-01-26",0.7885,{"date":384,"score":245,"percentile":385},"2026-01-27",0.78851,{"date":387,"score":245,"percentile":388},"2026-01-28",0.78853,{"date":390,"score":245,"percentile":391},"2026-01-29",0.78848,{"date":393,"score":245,"percentile":385},"2026-01-30",{"date":395,"score":245,"percentile":388},"2026-01-31",{"date":397,"score":310,"percentile":398},"2026-02-01",0.75248,[400,407],{"source":96,"cvss_v2_0":9,"cvss_v3_0":401,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":402,"baseSeverity":403,"vectorString":404,"impactScore":405,"exploitabilityScore":406},4.8,"MEDIUM","CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",4.2,5.6,{"source":91,"cvss_v2_0":408,"cvss_v3_0":413,"cvss_v3_1":414,"cvss_v4_0":9},{"baseScore":409,"baseSeverity":9,"vectorString":410,"impactScore":411,"exploitabilityScore":412},6.4,"AV:N/AC:L/Au:N/C:P/I:N/A:P",4.9,10,{"baseScore":402,"baseSeverity":403,"vectorString":404,"impactScore":405,"exploitabilityScore":406},{"baseScore":89,"baseSeverity":415,"vectorString":92,"impactScore":416,"exploitabilityScore":412},"CRITICAL",8.7,[418,429,437,447,460],{"ecosystem":9,"name":419,"vendor":420,"product":421,"cpe_part":422,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":423},"debian linux","debian","debian_linux","o",[424,427],{"version":425,"is_range":31,"range_type":426,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0","cpe",{"version":428,"is_range":31,"range_type":426,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0",{"ecosystem":9,"name":430,"vendor":431,"product":430,"cpe_part":422,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":432},"leap","opensuse",[433,435],{"version":434,"is_range":31,"range_type":426,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.0",{"version":436,"is_range":31,"range_type":426,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"15.1",{"ecosystem":9,"name":438,"vendor":9,"product":438,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":439},"PHP",[440,443,445],{"version":441,"is_range":31,"range_type":96,"version_start":441,"version_start_type":442,"version_end":441,"version_end_type":442,"fixed_in":9},"7.1.30","including",{"version":444,"is_range":31,"range_type":96,"version_start":444,"version_start_type":442,"version_end":444,"version_end_type":442,"fixed_in":9},"7.2.19",{"version":446,"is_range":31,"range_type":96,"version_start":446,"version_start_type":442,"version_end":446,"version_end_type":442,"fixed_in":9},"7.3.6",{"ecosystem":9,"name":438,"vendor":9,"product":438,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":448},[449,454,457],{"version":450,"is_range":451,"range_type":426,"version_start":452,"version_start_type":442,"version_end":441,"version_end_type":453,"fixed_in":9},"gte7.1.0_lt7.1.30",true,"7.1.0","excluding",{"version":455,"is_range":451,"range_type":426,"version_start":456,"version_start_type":442,"version_end":444,"version_end_type":453,"fixed_in":9},"gte7.2.0_lt7.2.19","7.2.0",{"version":458,"is_range":451,"range_type":426,"version_start":459,"version_start_type":442,"version_end":446,"version_end_type":453,"fixed_in":9},"gte7.3.0_lt7.3.6","7.3.0",{"ecosystem":9,"name":461,"vendor":462,"product":463,"cpe_part":464,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":465},"software collections","redhat","software_collections","a",[466],{"version":467,"is_range":31,"range_type":426,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"1.0"]