Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

fstec логотип

BDU:2022-02406

почти 10 лет назад

Уязвимость функции gdimagewebpctx графической библиотеки GD Graphics Library, интерпретатора языка программирования PHP , позволяющая нарушителю вызвать отказ в обслуживании или, возможно, оказать другое воздействие

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-9138

почти 10 лет назад

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2016-9137

около 10 лет назад

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2016-7418

около 10 лет назад

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5. ...

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2016-7418

около 10 лет назад

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2016-7417

около 10 лет назад

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceed ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-7417

около 10 лет назад

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-7416

около 10 лет назад

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x bef ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-7416

около 10 лет назад

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-7414

около 10 лет назад

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x be ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-02406

Уязвимость функции gdimagewebpctx графической библиотеки GD Graphics Library, интерпретатора языка программирования PHP , позволяющая нарушителю вызвать отказ в обслуживании или, возможно, оказать другое воздействие

CVSS3: 9.8
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9138

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.

CVSS3: 8.1
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9137

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.

CVSS3: 8.1
5%
Низкий
около 10 лет назад
debian логотип
CVE-2016-7418

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5. ...

CVSS3: 7.5
11%
Средний
около 10 лет назад
nvd логотип
CVE-2016-7418

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an incorrect boolean element in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call.

CVSS3: 7.5
11%
Средний
около 10 лет назад
debian логотип
CVE-2016-7417

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceed ...

CVSS3: 9.8
7%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-7417

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data.

CVSS3: 9.8
7%
Низкий
около 10 лет назад
debian логотип
CVE-2016-7416

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x bef ...

CVSS3: 7.5
7%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-7416

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a MessageFormatter::formatMessage call with a long first argument.

CVSS3: 7.5
7%
Низкий
около 10 лет назад
debian логотип
CVE-2016-7414

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x be ...

CVSS3: 9.8
7%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться