CVE-2018-12882

exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.


We have discovered 2,535,074 live websites that are affected by CVE-2018-12882.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains2,535,074 live websites (29.05% of PHP install base)
Vulnerable Versions
  • from 0 through 7.2.7
Vulnerable Versions Count327 versions ( 59.78% of all versions)



Details

  • Published - Jun 26, 2018
  • Updated - Aug 5, 2024

CVE-2018-12882 usage by Country

United States617,840 websites



Russia284,503 websites
France199,689 websites
Germany181,416 websites
Japan149,324 websites
Netherlands115,387 websites
Taiwan114,363 websites
China89,613 websites
GB61,443 websites
Poland45,272 websites

CVE-2018-12882 usage by TLD

.com1,053,405 websites
.ru242,984 websites
.de107,297 websites
.net90,793 websites
.nl81,050 websites
.fr72,229 websites
.org68,741 websites
.co.uk42,437 websites
.jp39,530 websites
.pl38,273 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-12882

Top websites that are affected by CVE-2018-12882. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org China***
*****.***********.com Canada***
**********.com United States***
**********.com United States***
************.***.ar Argentina*,***
*****.ru Russia*,***
********.*********.com Singapore*,***
******************.com United States*,***
***.org United States*,***
*********.******.net United States*,***
See full domain list

FAQ

A total of 2,535,074 websites have been identified as vulnerable to CVE-2018-12882, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2018-12882 vulnerability.
PHP versions before, and including, 7.2.7 are vulnerable to CVE-2018-12882.