Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 009

ubuntu логотип

CVE-2024-8929

почти 2 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2024-8929

почти 2 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2024-8932

почти 2 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-8932

почти 2 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-8932

почти 2 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-8932

почти 2 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h35g-vwh6-m678

почти 2 года назад

[Mysqlnd] Leak partial content of the heap through heap buffer over-read

EPSS: Низкий
github логотип

GHSA-g665-fm4p-vhff

почти 2 года назад

OOB access in ldap_escape

EPSS: Низкий
github логотип

GHSA-c5f2-jwm7-mmq2

почти 2 года назад

Configuring a proxy in a stream context might allow for CRLF injection in URIs

EPSS: Низкий
github логотип

GHSA-5hqh-c84r-qjcv

почти 2 года назад

Integer overflow in the firebird and dblib quoters causing OOB writes

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-8929

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
2%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-8929

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
2%
Низкий
почти 2 года назад
debian логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before ...

CVSS3: 9.8
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-h35g-vwh6-m678

[Mysqlnd] Leak partial content of the heap through heap buffer over-read

2%
Низкий
почти 2 года назад
github логотип
GHSA-g665-fm4p-vhff

OOB access in ldap_escape

1%
Низкий
почти 2 года назад
github логотип
GHSA-c5f2-jwm7-mmq2

Configuring a proxy in a stream context might allow for CRLF injection in URIs

1%
Низкий
почти 2 года назад
github логотип
GHSA-5hqh-c84r-qjcv

Integer overflow in the firebird and dblib quoters causing OOB writes

2%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться