CVE-2018-19396

ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.


We have discovered 2,336,345 live websites that are affected by CVE-2018-19396.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains2,336,345 live websites (26.77% of PHP install base)
Vulnerable Versions
  • from 0 through 7.1.24
Vulnerable Versions Count307 versions ( 56.12% of all versions)



Details

  • Published - Nov 21, 2018
  • Updated - Aug 5, 2024

CVE-2018-19396 usage by Country

United States577,360 websites



Russia257,624 websites
France170,183 websites
Germany166,961 websites
Japan134,502 websites
Taiwan113,912 websites
Netherlands101,018 websites
China83,720 websites
GB57,259 websites
Poland41,994 websites

CVE-2018-19396 usage by TLD

.com979,930 websites
.ru220,567 websites
.de100,118 websites
.net85,056 websites
.nl69,526 websites
.org63,111 websites
.fr61,314 websites
.co.uk38,938 websites
.jp35,850 websites
.pl35,138 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-19396

Top websites that are affected by CVE-2018-19396. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.org China***
*****.***********.com Canada***
**********.com United States***
**********.com United States***
************.***.ar Argentina*,***
*****.ru Russia*,***
********.*********.com Singapore*,***
******************.com United States*,***
***.org United States*,***
*********.******.net United States*,***
See full domain list

FAQ

A total of 2,336,345 websites have been identified as vulnerable to CVE-2018-19396, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2018-19396 vulnerability.
PHP versions before, and including, 7.1.24 are vulnerable to CVE-2018-19396.