Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 843

redhat логотип

CVE-2022-37454

почти 3 года назад

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-cj46-35hf-rv96

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-c43m-486j-j32p

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2022-31629

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2022-31628

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2022-31629

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2022-31629

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability en ...

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2022-31628

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 2.3
EPSS: Низкий
debian логотип

CVE-2022-31628

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompresso ...

CVSS3: 2.3
EPSS: Низкий
ubuntu логотип

CVE-2022-31629

почти 3 года назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2022-37454

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

CVSS3: 8.1
2%
Низкий
почти 3 года назад
github логотип
GHSA-cj46-35hf-rv96

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-c43m-486j-j32p

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
25%
Средний
почти 3 года назад
redhat логотип
CVE-2022-31629

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
25%
Средний
почти 3 года назад
redhat логотип
CVE-2022-31628

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-31629

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
25%
Средний
почти 3 года назад
debian логотип
CVE-2022-31629

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability en ...

CVSS3: 6.5
25%
Средний
почти 3 года назад
nvd логотип
CVE-2022-31628

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 2.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-31628

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompresso ...

CVSS3: 2.3
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-31629

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
25%
Средний
почти 3 года назад

Уязвимостей на страницу


Поделиться