PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 883
CVE-2014-3487
The cdf_read_property_info function in file before 5.19, as used in th ...
CVE-2014-3480
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
CVE-2014-3480
The cdf_count_chain function in cdf.c in file before 5.19, as used in ...
CVE-2014-3479
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
CVE-2014-3479
The cdf_check_stream_offset function in cdf.c in file before 5.19, as ...
CVE-2014-3478
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
CVE-2014-3478
Buffer overflow in the mconvert function in softmagic.c in file before ...
CVE-2014-0207
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.
CVE-2014-0207
The cdf_read_short_sector function in cdf.c in file before 5.19, as us ...
CVE-2014-3480
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2014-3487 The cdf_read_property_info function in file before 5.19, as used in th ... | CVSS2: 4.3 | 19% Средний | больше 11 лет назад | |
CVE-2014-3480 The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. | CVSS3: 6.5 | 6% Низкий | больше 11 лет назад | |
CVE-2014-3480 The cdf_count_chain function in cdf.c in file before 5.19, as used in ... | CVSS3: 6.5 | 6% Низкий | больше 11 лет назад | |
CVE-2014-3479 The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file. | CVSS2: 4.3 | 10% Средний | больше 11 лет назад | |
CVE-2014-3479 The cdf_check_stream_offset function in cdf.c in file before 5.19, as ... | CVSS2: 4.3 | 10% Средний | больше 11 лет назад | |
CVE-2014-3478 Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion. | CVSS3: 6.5 | 25% Средний | больше 11 лет назад | |
CVE-2014-3478 Buffer overflow in the mconvert function in softmagic.c in file before ... | CVSS3: 6.5 | 25% Средний | больше 11 лет назад | |
CVE-2014-0207 The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file. | CVSS3: 6.5 | 7% Низкий | больше 11 лет назад | |
CVE-2014-0207 The cdf_read_short_sector function in cdf.c in file before 5.19, as us ... | CVSS3: 6.5 | 7% Низкий | больше 11 лет назад | |
CVE-2014-3480 The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. | CVSS3: 6.5 | 6% Низкий | больше 11 лет назад |
Уязвимостей на страницу