Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

debian логотип

CVE-2021-21704

почти 5 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below ...

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2021-21704

почти 5 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2021-21704

почти 5 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2021-21706

почти 5 лет назад

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-21705

почти 5 лет назад

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2021-06176

около 5 лет назад

Уязвимость функции ZipArchive::extractTo интерпретатора PHP, позволяющая нарушителю создать или перезаписать файлы

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2795-1

около 5 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2795-1

около 5 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2638-1

около 5 лет назад

Security update for php72

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2575-1

около 5 лет назад

Security update for php7

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-21704

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below ...

CVSS3: 5
2%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-21704

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5
2%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-21704

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.

CVSS3: 5
2%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-21706

In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially causing files to be created or overwritten, subject to OS permissions.

CVSS3: 5.3
1%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-21705

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.

CVSS3: 4.3
2%
Низкий
почти 5 лет назад
fstec логотип
BDU:2021-06176

Уязвимость функции ZipArchive::extractTo интерпретатора PHP, позволяющая нарушителю создать или перезаписать файлы

CVSS3: 5.3
1%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2795-1

Security update for php7

2%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2795-1

Security update for php7

2%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:2638-1

Security update for php72

2%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2575-1

Security update for php7

2%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться