PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 883
CVE-2016-4537
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
CVE-2016-4537
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6 ...
CVE-2016-4346
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
CVE-2016-4346
Integer overflow in the str_pad function in ext/standard/string.c in P ...
CVE-2016-4345
Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
CVE-2016-4345
Integer overflow in the php_filter_encode_url function in ext/filter/s ...
CVE-2016-4344
Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argument to the utf8_encode function, leading to a heap-based buffer overflow.
CVE-2016-4344
Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in P ...
CVE-2016-4343
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive.
CVE-2016-4343
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-4537 The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call. | CVSS3: 9.8 | 6% Низкий | больше 9 лет назад | |
CVE-2016-4537 The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6 ... | CVSS3: 9.8 | 6% Низкий | больше 9 лет назад | |
CVE-2016-4346 Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow. | CVSS3: 9.8 | 1% Низкий | больше 9 лет назад | |
CVE-2016-4346 Integer overflow in the str_pad function in ext/standard/string.c in P ... | CVSS3: 9.8 | 1% Низкий | больше 9 лет назад | |
CVE-2016-4345 Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow. | CVSS3: 9.8 | 1% Низкий | больше 9 лет назад | |
CVE-2016-4345 Integer overflow in the php_filter_encode_url function in ext/filter/s ... | CVSS3: 9.8 | 1% Низкий | больше 9 лет назад | |
CVE-2016-4344 Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argument to the utf8_encode function, leading to a heap-based buffer overflow. | CVSS3: 9.8 | 1% Низкий | больше 9 лет назад | |
CVE-2016-4344 Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in P ... | CVSS3: 9.8 | 1% Низкий | больше 9 лет назад | |
CVE-2016-4343 The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive. | CVSS3: 8.8 | 8% Низкий | больше 9 лет назад | |
CVE-2016-4343 The phar_make_dirstream function in ext/phar/dirstream.c in PHP before ... | CVSS3: 8.8 | 8% Низкий | больше 9 лет назад |
Уязвимостей на страницу