CVE-2018-19396

ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.


We have discovered 1,692,291 live websites that are affected by CVE-2018-19396.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains1,692,291 live websites (23% of PHP install base)
Vulnerable Versions
  • from 5 through 7.1.24
Vulnerable Versions Count249 versions ( 49% of all versions)



Details

  • Published - Nov 20, 2018
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2018-19396
United States345,630 websites



Russia210,675 websites
France124,282 websites
Taiwan112,188 websites
Japan109,264 websites
Germany108,728 websites
Netherlands71,547 websites
China63,308 websites
GB45,288 websites
Italy36,468 websites

Website Distribution by TLD

Number of websites using CVE-2018-19396
.com704,080 websites
.ru176,686 websites
.de66,314 websites
.net57,075 websites
.fr47,787 websites
.org45,709 websites
.nl45,462 websites
.jp28,991 websites
.co.uk28,376 websites
.it26,298 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-19396

Top websites that are affected by CVE-2018-19396. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org China***
*****.***********.com Canada***
**********.com United States***
******************.com United States*,***
***.org Italy*,***
*********.******.net United States*,***
****.com United States*,***
********.com United States*,***
********.org United States*,***
******.de Germany*,***
See full domain list

FAQ

A total of 1,692,291 websites have been identified as vulnerable to CVE-2018-19396, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2018-19396 vulnerability.
PHP versions up to and including 7.1.24 are vulnerable to CVE-2018-19396.