Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

debian логотип

CVE-2015-1352

больше 11 лет назад

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0273

больше 11 лет назад

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2015-2348

больше 11 лет назад

The move_uploaded_file implementation in ext/standard/basic_functions. ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-2301

больше 11 лет назад

Use-after-free vulnerability in the phar_rename_archive function in ph ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-9705

больше 11 лет назад

Heap-based buffer overflow in the enchant_broker_request_dict function ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-9709

больше 11 лет назад

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2013-6501

больше 11 лет назад

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-2331

больше 11 лет назад

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2015-2301

больше 11 лет назад

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2014-9653

больше 11 лет назад

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-1352

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) ...

CVSS2: 5
7%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0273

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP ...

CVSS2: 7.5
43%
Средний
больше 11 лет назад
debian логотип
CVE-2015-2348

The move_uploaded_file implementation in ext/standard/basic_functions. ...

CVSS2: 5
9%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2301

Use-after-free vulnerability in the phar_rename_archive function in ph ...

CVSS2: 7.5
15%
Средний
больше 11 лет назад
debian логотип
CVE-2014-9705

Heap-based buffer overflow in the enchant_broker_request_dict function ...

CVSS2: 7.5
19%
Средний
больше 11 лет назад
debian логотип
CVE-2014-9709

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used ...

CVSS2: 5
15%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2013-6501

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 4.6
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-2331

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

CVSS2: 7.5
28%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2015-2301

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.

CVSS2: 7.5
15%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-9653

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file.

CVSS2: 7.5
5%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться