Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

debian логотип

CVE-2015-1351

почти 11 лет назад

Use-after-free vulnerability in the _zend_shared_memdup function in ze ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2015-0273

почти 11 лет назад

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.

CVSS2: 7.5
EPSS: Высокий
debian логотип

CVE-2015-0273

почти 11 лет назад

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP ...

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2014-9709

почти 11 лет назад

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-9709

почти 11 лет назад

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2014-9705

почти 11 лет назад

Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-9705

почти 11 лет назад

Heap-based buffer overflow in the enchant_broker_request_dict function ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2014-9653

почти 11 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-9653

почти 11 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PH ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-9652

почти 11 лет назад

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-1351

Use-after-free vulnerability in the _zend_shared_memdup function in ze ...

CVSS2: 7.5
19%
Средний
почти 11 лет назад
nvd логотип
CVE-2015-0273

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.

CVSS2: 7.5
71%
Высокий
почти 11 лет назад
debian логотип
CVE-2015-0273

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP ...

CVSS2: 7.5
71%
Высокий
почти 11 лет назад
nvd логотип
CVE-2014-9709

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

CVSS2: 5
17%
Средний
почти 11 лет назад
debian логотип
CVE-2014-9709

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used ...

CVSS2: 5
17%
Средний
почти 11 лет назад
nvd логотип
CVE-2014-9705

Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVSS2: 7.5
35%
Средний
почти 11 лет назад
debian логотип
CVE-2014-9705

Heap-based buffer overflow in the enchant_broker_request_dict function ...

CVSS2: 7.5
35%
Средний
почти 11 лет назад
nvd логотип
CVE-2014-9653

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

CVSS2: 7.5
7%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-9653

readelf.c in file before 5.22, as used in the Fileinfo component in PH ...

CVSS2: 7.5
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-9652

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file.

CVSS2: 5
6%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться