PHP minor releases are bug and security fixes. But as long as the latest minor release fixed a vulnerability, in 99% of the cases, you can assume that all previous versions contain that vulnerability. (I know, I know, regressions do happen)
So for PHP's 5.6 line, only 5.6.4 is secure, since 5.6.4 is a security release.
I'm currently crunching numbers for other platforms. For example, Nginx's last security release (for 1.7) was 1.7.5, so 1.7.5 -> 1.7.9 are all considered security.
Note that this list refers to those versions as released, not as OS vendors may have patched them.
But don't take my word for it... http://php.net/ChangeLog-5.php
At least 90% of releases have a bugfix with an associated CVE vulnerability.