CVE-2017-9118 is an Out-of-Bounds access vulnerability in PHP 7.1.5, specifically within the php_pcre_replace_impl function, exploitable through a crafted preg_replace call. This vulnerability affects PHP and NetApp products utilizing the vulnerable PHP version. With a CVSS score of 7.5 (High), it presents a network-exploitable, low-complexity attack that can lead to high availability impact, though it does not compromise confidentiality or integrity. Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.4.0, < 7.4.27CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.14CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.1CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
7.1.5CPE matchmatch criteria | cpe:2.3:a:php:php:7.1.5:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.