Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

nvd логотип

CVE-2015-4605

больше 9 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4605

больше 9 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4604

больше 9 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4604

больше 9 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4603

больше 9 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-4603

больше 9 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-4602

больше 9 лет назад

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-4602

больше 9 лет назад

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2015-4601

больше 9 лет назад

PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-4601

больше 9 лет назад

PHP before 5.6.7 might allow remote attackers to cause a denial of ser ...

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
9%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-4602

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
13%
Средний
больше 9 лет назад
debian логотип
CVE-2015-4602

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c ...

CVSS3: 9.8
13%
Средний
больше 9 лет назад
nvd логотип
CVE-2015-4601

PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.

CVSS3: 9.8
21%
Средний
больше 9 лет назад
debian логотип
CVE-2015-4601

PHP before 5.6.7 might allow remote attackers to cause a denial of ser ...

CVSS3: 9.8
21%
Средний
больше 9 лет назад

Уязвимостей на страницу


Поделиться