Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

redhat логотип

CVE-2018-14884

почти 9 лет назад

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-16642

почти 9 лет назад

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an e ...

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2017-16642

почти 9 лет назад

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2017-16642

почти 9 лет назад

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2017-16642

почти 9 лет назад

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 2.9
EPSS: Средний
fstec логотип

BDU:2022-02423

почти 9 лет назад

Уязвимость компонента ext/date/lib/parse_date.c интерпретатора языка программирования PHP, позволяющая нарушителю оказать воздействие на конфиденциальность информации

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2017:2536-1

около 9 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2518-1

около 9 лет назад

Security update for php5

EPSS: Низкий
debian логотип

CVE-2017-12868

около 9 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-12868

около 9 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2018-14884

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-16642

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an e ...

CVSS3: 7.5
26%
Средний
почти 9 лет назад
nvd логотип
CVE-2017-16642

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 7.5
26%
Средний
почти 9 лет назад
ubuntu логотип
CVE-2017-16642

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 7.5
26%
Средний
почти 9 лет назад
redhat логотип
CVE-2017-16642

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_date.c out-of-bounds reads affecting the php_parse_date function. NOTE: this is a different issue than CVE-2017-11145.

CVSS3: 2.9
26%
Средний
почти 9 лет назад
fstec логотип
BDU:2022-02423

Уязвимость компонента ext/date/lib/parse_date.c интерпретатора языка программирования PHP, позволяющая нарушителю оказать воздействие на конфиденциальность информации

CVSS3: 7.5
26%
Средний
почти 9 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2536-1

Security update for php5

7%
Низкий
около 9 лет назад
suse-cvrf логотип
SUSE-SU-2017:2518-1

Security update for php5

7%
Низкий
около 9 лет назад
debian логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

CVSS3: 9.8
2%
Низкий
около 9 лет назад
nvd логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
2%
Низкий
около 9 лет назад

Уязвимостей на страницу


Поделиться