Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 867

redhat логотип

CVE-2019-13224

больше 6 лет назад

A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2020-01414

больше 6 лет назад

Уязвимость функции exif_read_data интерпретатора PHP, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить несанкционированный доступ к информации или вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11040

больше 6 лет назад

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-11040

больше 6 лет назад

When PHP EXIF extension is parsing EXIF information from an image, e.g ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-11039

больше 6 лет назад

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2019-11039

больше 6 лет назад

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.3 ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2019-11038

больше 6 лет назад

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11038

больше 6 лет назад

When using the gdImageCreateFromXbm() function in the GD Graphics Libr ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2019-11039

больше 6 лет назад

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2019-11038

больше 6 лет назад

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2019-13224

A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

CVSS3: 6.8
1%
Низкий
больше 6 лет назад
fstec логотип
BDU:2020-01414

Уязвимость функции exif_read_data интерпретатора PHP, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить несанкционированный доступ к информации или вызвать отказ в обслуживании

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11040

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

CVSS3: 9.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11040

When PHP EXIF extension is parsing EXIF information from an image, e.g ...

CVSS3: 9.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11039

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.

CVSS3: 9.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11039

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.3 ...

CVSS3: 9.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CVSS3: 5.3
8%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Libr ...

CVSS3: 5.3
8%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11039

Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.

CVSS3: 9.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

CVSS3: 5.3
8%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться