Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 889

debian логотип

CVE-2014-3479

больше 11 лет назад

The cdf_check_stream_offset function in cdf.c in file before 5.19, as ...

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2014-3478

больше 11 лет назад

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2014-3478

больше 11 лет назад

Buffer overflow in the mconvert function in softmagic.c in file before ...

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2014-0207

больше 11 лет назад

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2014-0207

больше 11 лет назад

The cdf_read_short_sector function in cdf.c in file before 5.19, as us ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2014-3480

больше 11 лет назад

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-0207

больше 11 лет назад

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2014-3478

больше 11 лет назад

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2014-3515

больше 11 лет назад

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2014-3479

больше 11 лет назад

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-3479

The cdf_check_stream_offset function in cdf.c in file before 5.19, as ...

CVSS2: 4.3
10%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-3478

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.

CVSS3: 6.5
25%
Средний
больше 11 лет назад
debian логотип
CVE-2014-3478

Buffer overflow in the mconvert function in softmagic.c in file before ...

CVSS3: 6.5
25%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0207

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVSS3: 6.5
12%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0207

The cdf_read_short_sector function in cdf.c in file before 5.19, as us ...

CVSS3: 6.5
12%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3480

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

CVSS3: 6.5
6%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-0207

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVSS3: 6.5
12%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3478

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.

CVSS3: 6.5
25%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3515

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 7.5
61%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3479

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.

CVSS2: 4.3
10%
Средний
больше 11 лет назад

Уязвимостей на страницу


Поделиться