Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 889

ubuntu логотип

CVE-2011-1398

больше 13 лет назад

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3450

больше 13 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
EPSS: Средний
debian логотип

CVE-2012-3450

больше 13 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x ...

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2012-3450

больше 13 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2011-1398

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome.

CVSS2: 4.3
9%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
12%
Средний
больше 13 лет назад
debian логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x ...

CVSS2: 2.6
12%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
12%
Средний
больше 13 лет назад
nvd логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers ...

CVSS2: 5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
33%
Средний
больше 13 лет назад
debian логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
33%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
33%
Средний
больше 13 лет назад

Уязвимостей на страницу


Поделиться