Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

redhat логотип

CVE-2019-11049

почти 7 лет назад

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2011-1939

почти 7 лет назад

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-1939

почти 7 лет назад

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2011-1939

почти 7 лет назад

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-19246

почти 7 лет назад

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-19246

почти 7 лет назад

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-19246

почти 7 лет назад

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-11044

почти 7 лет назад

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

EPSS: Низкий
oracle-oval логотип

ELSA-2019-3735

почти 7 лет назад

ELSA-2019-3735: php:7.2 security update (CRITICAL)

EPSS: Критический
oracle-oval логотип

ELSA-2019-3736

почти 7 лет назад

ELSA-2019-3736: php:7.3 security update (CRITICAL)

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2019-11049

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

CVSS3: 6.5
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2011-1939

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and ...

CVSS3: 9.8
4%
Низкий
почти 7 лет назад
nvd логотип
CVE-2011-1939

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
4%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2011-1939

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
4%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-19246

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has ...

CVSS3: 7.5
3%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-19246

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

CVSS3: 7.5
3%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-19246

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

CVSS3: 7.5
3%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-11044

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

5%
Низкий
почти 7 лет назад
oracle-oval логотип
ELSA-2019-3735

ELSA-2019-3735: php:7.2 security update (CRITICAL)

100%
Критический
почти 7 лет назад
oracle-oval логотип
ELSA-2019-3736

ELSA-2019-3736: php:7.3 security update (CRITICAL)

100%
Критический
почти 7 лет назад

Уязвимостей на страницу


Поделиться