Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 984

ubuntu логотип

CVE-2019-19246

больше 6 лет назад

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-11044

больше 6 лет назад

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

EPSS: Низкий
oracle-oval логотип

ELSA-2019-3736

больше 6 лет назад

ELSA-2019-3736: php:7.3 security update (CRITICAL)

EPSS: Критический
oracle-oval логотип

ELSA-2019-3735

больше 6 лет назад

ELSA-2019-3735: php:7.2 security update (CRITICAL)

EPSS: Критический
nvd логотип

CVE-2010-4657

больше 6 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2010-4657

больше 6 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlText ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4657

больше 6 лет назад

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-02599

больше 6 лет назад

Уязвимость компонента XMLWriter интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2457-1

больше 6 лет назад

Security update for php7

EPSS: Критический
redhat логотип

CVE-2019-11050

больше 6 лет назад

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-19246

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

CVSS3: 7.5
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-11044

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

5%
Низкий
больше 6 лет назад
oracle-oval логотип
ELSA-2019-3736

ELSA-2019-3736: php:7.3 security update (CRITICAL)

99%
Критический
больше 6 лет назад
oracle-oval логотип
ELSA-2019-3735

ELSA-2019-3735: php:7.2 security update (CRITICAL)

99%
Критический
больше 6 лет назад
nvd логотип
CVE-2010-4657

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2010-4657

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlText ...

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2010-4657

PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
fstec логотип
BDU:2022-02599

Уязвимость компонента XMLWriter интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2457-1

Security update for php7

99%
Критический
больше 6 лет назад
redhat логотип
CVE-2019-11050

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

CVSS3: 6.5
8%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться