Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 867

debian логотип

CVE-2016-3171

больше 9 лет назад

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-3167

больше 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2016-3167

больше 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2016-3167

больше 9 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2016-3171

больше 9 лет назад

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-3142

больше 9 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2016-3142

больше 9 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP ...

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2016-3141

больше 9 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2016-3141

больше 9 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP be ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2016-3141

больше 9 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-3171

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before ...

CVSS3: 8.1
8%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-3167

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
1%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-3167

Open redirect vulnerability in the drupal_goto function in Drupal 6.x ...

CVSS3: 7.4
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-3167

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-3171

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

CVSS3: 8.1
8%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-3142

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-3142

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP ...

CVSS3: 8.2
3%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-3141

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
44%
Средний
больше 9 лет назад
debian логотип
CVE-2016-3141

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP be ...

CVSS3: 9.8
44%
Средний
больше 9 лет назад
ubuntu логотип
CVE-2016-3141

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
44%
Средний
больше 9 лет назад

Уязвимостей на страницу


Поделиться