In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.
We have discovered 479,641 live websites that are affected by CVE-2022-31630.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 479,641 live websites (6.19% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 68 versions ( 14% of all versions) |
| 190,118 websites | |
| 133,928 websites | |
| 14,678 websites | |
| 14,581 websites | |
| 9,267 websites | |
| 9,083 websites | |
| 8,528 websites | |
| 8,459 websites | |
| 7,988 websites | |
| 7,361 websites |
| .com | 239,921 websites |
| .fr | 55,605 websites |
| .org | 27,579 websites |
| .net | 14,687 websites |
| .ru | 11,994 websites |
| .de | 8,834 websites |
| .pl | 7,708 websites |
| .be | 6,951 websites |
| .com.br | 6,860 websites |
| .nl | 6,762 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.pl | *,*** | ||
| ****.org | *,*** | ||
| **********.org | *,*** | ||
| ******.com | *,*** | ||
| **********.com | *,*** | ||
| *******.pro | *,*** | ||
| ***************.com | *,*** | ||
| *********.de | *,*** | ||
| ******.jp | *,*** | ||
| ******.at | *,*** |
FAQ