Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-3182

36
FAUCET Score

CVE-2011-3182 describes a vulnerability in PHP versions prior to 5.3.7, where improper handling of memory allocation function return values can lead to a denial of service via NULL pointer dereference or buffer overflow. This vulnerability affects various PHP extensions and the strtotime function. With a CVSS score of 5.0, it is a medium-severity issue that can be exploited remotely without authentication, resulting in an application crash. While not actively exploited, public exploit code exists, and there is minimal community discussion or media coverage surrounding this decade-old vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.3.6CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
1.0CPE matchmatch criteria
cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:*
2.0b10CPE matchmatch criteria
cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
19.15%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-36070 · Aug 19, 2011
This CVE's current EPSS score of 0.1915 is in the 97th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2011-3182

php: multiple NULL pointer dereferences

Aug 19, 2011

References

lists.apple.com / archives/security-announce/2012/Feb/msg00000.html
marc.info
Exploit
securityreason.com / achievement_securityalert/101
Exploit
exchange.xforce.ibmcloud.com / vulnerabilities/69430
support.apple.com / kb/HT5130
mandriva.com / security/advisories
openwall.com / lists/oss-security/2011/08/22/9
Exploit
securityfocus.com / bid/49249
Exploit