Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 999

debian логотип

CVE-2016-3167

больше 10 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2016-3171

больше 10 лет назад

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2016-3167

больше 10 лет назад

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2016-3142

больше 10 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2016-3142

больше 10 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP ...

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2016-3141

больше 10 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2016-3141

больше 10 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP be ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2016-3141

больше 10 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2016-3142

больше 10 лет назад

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
EPSS: Низкий
fstec логотип

BDU:2016-00908

больше 10 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю получить конфиденциальную информацию или вызвать отказ в обслуживании

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-3167

Open redirect vulnerability in the drupal_goto function in Drupal 6.x ...

CVSS3: 7.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3171

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

CVSS3: 8.1
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3167

Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

CVSS3: 7.4
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-3142

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
5%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-3142

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP ...

CVSS3: 8.2
5%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-3141

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
36%
Средний
больше 10 лет назад
debian логотип
CVE-2016-3141

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP be ...

CVSS3: 9.8
36%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-3141

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
36%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-3142

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

CVSS3: 8.2
5%
Низкий
больше 10 лет назад
fstec логотип
BDU:2016-00908

Уязвимость интерпретатора PHP, позволяющая нарушителю получить конфиденциальную информацию или вызвать отказ в обслуживании

CVSS2: 6.4
5%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться