Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

redhat логотип

CVE-2016-7414

около 10 лет назад

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via a crafted PHAR archive, related to ext/phar/util.c and ext/phar/zip.c.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2016-7413

около 10 лет назад

Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document that lacks an end-tag for a recordset field element, leading to mishandling in a wddx_deserialize call.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2016-6207

около 10 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpola ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-6207

около 10 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-6207

около 10 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2016-1609

около 10 лет назад

ELSA-2016-1609: php security update (MODERATE)

EPSS: Средний
oracle-oval логотип

ELSA-2016-1613

около 10 лет назад

ELSA-2016-1613: php security and bug fix update (MODERATE)

EPSS: Средний
debian логотип

CVE-2016-6128

около 10 лет назад

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Libr ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-6128

около 10 лет назад

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-5773

около 10 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6. ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2016-7414

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via a crafted PHAR archive, related to ext/phar/util.c and ext/phar/zip.c.

CVSS3: 5.9
7%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-7413

Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document that lacks an end-tag for a recordset field element, leading to mishandling in a wddx_deserialize call.

CVSS3: 5.9
7%
Низкий
около 10 лет назад
debian логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpola ...

CVSS3: 6.5
6%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
6%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
6%
Низкий
около 10 лет назад
oracle-oval логотип
ELSA-2016-1609

ELSA-2016-1609: php security update (MODERATE)

50%
Средний
около 10 лет назад
oracle-oval логотип
ELSA-2016-1613

ELSA-2016-1613: php security and bug fix update (MODERATE)

50%
Средний
около 10 лет назад
debian логотип
CVE-2016-6128

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Libr ...

CVSS3: 7.5
7%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-6128

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
7%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5773

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6. ...

CVSS3: 9.8
9%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться