Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 987

nvd логотип

CVE-2014-3710

почти 12 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-3710

почти 12 лет назад

The donote function in readelf.c in file through 5.20, as used in the ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-3710

почти 12 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2014-8626

почти 12 лет назад

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-3670

почти 12 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2014-3670

почти 12 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PH ...

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2014-3669

почти 12 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-3669

почти 12 лет назад

Integer overflow in the object_custom function in ext/standard/var_uns ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2014-3668

почти 12 лет назад

Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-3668

почти 12 лет назад

Buffer overflow in the date_from_ISO8601 function in the mkgmtime impl ...

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
14%
Средний
почти 12 лет назад
debian логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the ...

CVSS2: 5
14%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
14%
Средний
почти 12 лет назад
redhat логотип
CVE-2014-8626

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

CVSS2: 6.8
6%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
23%
Средний
почти 12 лет назад
debian логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PH ...

CVSS2: 6.8
23%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-3669

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 7.5
29%
Средний
почти 12 лет назад
debian логотип
CVE-2014-3669

Integer overflow in the object_custom function in ext/standard/var_uns ...

CVSS2: 7.5
29%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-3668

Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.

CVSS2: 5
27%
Средний
почти 12 лет назад
debian логотип
CVE-2014-3668

Buffer overflow in the date_from_ISO8601 function in the mkgmtime impl ...

CVSS2: 5
27%
Средний
почти 12 лет назад

Уязвимостей на страницу


Поделиться