Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 867

suse-cvrf логотип

SUSE-SU-2017:2518-1

около 8 лет назад

Security update for php5

EPSS: Средний
nvd логотип

CVE-2017-12868

около 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-12868

около 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12868

около 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-12934

больше 8 лет назад

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-12934

больше 8 лет назад

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-12933

больше 8 лет назад

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2017-12933

больше 8 лет назад

The finish_nested_data function in ext/standard/var_unserializer.re in ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2017-12932

больше 8 лет назад

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-12932

больше 8 лет назад

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
SUSE-SU-2017:2518-1

Security update for php5

17%
Средний
около 8 лет назад
nvd логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

CVSS3: 9.8
1%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-12934

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-12934

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x ...

CVSS3: 7.5
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-12933

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 9.8
17%
Средний
больше 8 лет назад
debian логотип
CVE-2017-12933

The finish_nested_data function in ext/standard/var_unserializer.re in ...

CVSS3: 9.8
17%
Средний
больше 8 лет назад
nvd логотип
CVE-2017-12932

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 9.8
2%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-12932

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x ...

CVSS3: 9.8
2%
Низкий
больше 8 лет назад

Уязвимостей на страницу


Поделиться