Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 987

ubuntu логотип

CVE-2017-16642

больше 8 лет назад

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2017-16642

почти 9 лет назад

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 2.9
EPSS: Средний
fstec логотип

BDU:2022-02423

почти 9 лет назад

Уязвимость компонента ext/date/lib/parse_date.c интерпретатора языка программирования PHP, позволяющая нарушителю оказать воздействие на конфиденциальность информации

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2017:2536-1

почти 9 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2518-1

почти 9 лет назад

Security update for php5

EPSS: Низкий
nvd логотип

CVE-2017-12868

почти 9 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-12868

почти 9 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12868

почти 9 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-12934

почти 9 лет назад

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-12934

почти 9 лет назад

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2017-16642

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 7.5
26%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-16642

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 2.9
26%
Средний
почти 9 лет назад
fstec логотип
BDU:2022-02423

Уязвимость компонента ext/date/lib/parse_date.c интерпретатора языка программирования PHP, позволяющая нарушителю оказать воздействие на конфиденциальность информации

CVSS3: 7.5
26%
Средний
почти 9 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2536-1

Security update for php5

7%
Низкий
почти 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:2518-1

Security update for php5

7%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-12934

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

CVSS3: 7.5
4%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-12934

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x ...

CVSS3: 7.5
4%
Низкий
почти 9 лет назад

Уязвимостей на страницу


Поделиться