Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

nvd логотип

CVE-2015-4643

больше 10 лет назад

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-4642

больше 10 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.4 ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-4642

больше 10 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-4605

больше 10 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4605

больше 10 лет назад

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4604

больше 10 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4604

больше 10 лет назад

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4603

больше 10 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2015-4603

больше 10 лет назад

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-4602

больше 10 лет назад

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c ...

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4643

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.

CVSS3: 9.8
16%
Средний
больше 10 лет назад
debian логотип
CVE-2015-4642

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.4 ...

CVSS3: 9.8
6%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-4642

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
6%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-4605

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo ...

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-4604

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in ...

CVSS3: 9.8
11%
Средний
больше 10 лет назад
nvd логотип
CVE-2015-4603

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

CVSS3: 9.8
11%
Средний
больше 10 лет назад
debian логотип
CVE-2015-4602

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c ...

CVSS3: 9.8
11%
Средний
больше 10 лет назад

Уязвимостей на страницу


Поделиться