Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

nvd логотип

CVE-2016-9936

около 9 лет назад

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-9936

около 9 лет назад

The unserialize implementation in ext/standard/var.c in PHP 7.x before ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-9935

около 9 лет назад

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty boolean element in a wddxPacket XML document.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-9935

около 9 лет назад

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5. ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-9934

около 9 лет назад

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2016-9934

около 9 лет назад

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remo ...

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2016-9933

около 9 лет назад

Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2016-9933

около 9 лет назад

Stack consumption vulnerability in the gdImageFillToBorder function in ...

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2016-9138

около 9 лет назад

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-9138

около 9 лет назад

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modifica ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2016-9936

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.

CVSS3: 9.8
1%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9936

The unserialize implementation in ext/standard/var.c in PHP 7.x before ...

CVSS3: 9.8
1%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9935

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty boolean element in a wddxPacket XML document.

CVSS3: 9.8
4%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9935

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5. ...

CVSS3: 9.8
4%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-9934

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

CVSS3: 7.5
12%
Средний
около 9 лет назад
debian логотип
CVE-2016-9934

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remo ...

CVSS3: 7.5
12%
Средний
около 9 лет назад
nvd логотип
CVE-2016-9933

Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.

CVSS3: 7.5
11%
Средний
около 9 лет назад
debian логотип
CVE-2016-9933

Stack consumption vulnerability in the gdImageFillToBorder function in ...

CVSS3: 7.5
11%
Средний
около 9 лет назад
nvd логотип
CVE-2016-9138

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.

CVSS3: 9.8
4%
Низкий
около 9 лет назад
debian логотип
CVE-2016-9138

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modifica ...

CVSS3: 9.8
4%
Низкий
около 9 лет назад

Уязвимостей на страницу


Поделиться