Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 867

nvd логотип

CVE-2015-8617

почти 10 лет назад

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-8617

почти 10 лет назад

Format string vulnerability in the zend_throw_or_error function in Zen ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2015-8616

почти 10 лет назад

Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging the relationships between a key buffer and a destroyed array.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2015-8616

почти 10 лет назад

Use-after-free vulnerability in the Collator::sortWithSortKeys functio ...

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2015-6836

почти 10 лет назад

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2015-6836

почти 10 лет назад

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2015-6833

почти 10 лет назад

Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2015-6833

почти 10 лет назад

Directory traversal vulnerability in the PharData class in PHP before ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-6832

почти 10 лет назад

Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers misuse of an array field.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2015-6832

почти 10 лет назад

Use-after-free vulnerability in the SPL unserialize implementation in ...

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-8617

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.

CVSS3: 9.8
27%
Средний
почти 10 лет назад
debian логотип
CVE-2015-8617

Format string vulnerability in the zend_throw_or_error function in Zen ...

CVSS3: 9.8
27%
Средний
почти 10 лет назад
nvd логотип
CVE-2015-8616

Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging the relationships between a key buffer and a destroyed array.

CVSS3: 8.6
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-8616

Use-after-free vulnerability in the Collator::sortWithSortKeys functio ...

CVSS3: 8.6
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-6836

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

CVSS3: 7.3
3%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-6836

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, ...

CVSS3: 7.3
3%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-6833

Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extractTo call.

CVSS3: 7.5
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-6833

Directory traversal vulnerability in the PharData class in PHP before ...

CVSS3: 7.5
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2015-6832

Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers misuse of an array field.

CVSS3: 7.3
2%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-6832

Use-after-free vulnerability in the SPL unserialize implementation in ...

CVSS3: 7.3
2%
Низкий
почти 10 лет назад

Уязвимостей на страницу


Поделиться