Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 867

nvd логотип

CVE-2015-4643

больше 9 лет назад

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-4643

больше 9 лет назад

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP b ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-4642

больше 9 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-4642

больше 9 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.4 ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-4605

больше 9 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4605

больше 9 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4604

больше 9 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4604

больше 9 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4603

больше 9 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-4603

больше 9 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4643

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.

CVSS3: 9.8
9%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4643

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP b ...

CVSS3: 9.8
9%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4642

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
6%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4642

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.4 ...

CVSS3: 9.8
6%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
8%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться