Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 000

debian логотип

CVE-2015-4643

около 10 лет назад

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP b ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2015-4642

около 10 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-4642

около 10 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.4 ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-4605

около 10 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4605

около 10 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4604

около 10 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4604

около 10 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4603

около 10 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-4603

около 10 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2015-4602

около 10 лет назад

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-4643

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP b ...

CVSS3: 9.8
17%
Средний
около 10 лет назад
nvd логотип
CVE-2015-4642

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
6%
Низкий
около 10 лет назад
debian логотип
CVE-2015-4642

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.4 ...

CVSS3: 9.8
6%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
7%
Низкий
около 10 лет назад
debian логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
7%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
7%
Низкий
около 10 лет назад
debian логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
7%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
11%
Средний
около 10 лет назад
debian логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
11%
Средний
около 10 лет назад
nvd логотип
CVE-2015-4602

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
11%
Средний
около 10 лет назад

Уязвимостей на страницу


Поделиться