PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 984
CVE-2013-4113
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing ...
CVE-2013-4113
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
ELSA-2013-1050
ELSA-2013-1050: php53 security update (CRITICAL)
ELSA-2013-1049
ELSA-2013-1049: php security update (CRITICAL)
CVE-2013-4113
ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.
CVE-2013-4636
The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.
CVE-2013-4636
The mget function in libmagic/softmagic.c in the Fileinfo component in ...
CVE-2013-4635
Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.
CVE-2013-4635
Integer overflow in the SdnToJewish function in jewish.c in the Calend ...
CVE-2013-4635
Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2013-4113 ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing ... | CVSS2: 6.8 | 5% Низкий | около 13 лет назад | |
CVE-2013-4113 ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function. | CVSS2: 6.8 | 5% Низкий | около 13 лет назад | |
ELSA-2013-1050 ELSA-2013-1050: php53 security update (CRITICAL) | 5% Низкий | около 13 лет назад | ||
ELSA-2013-1049 ELSA-2013-1049: php security update (CRITICAL) | 5% Низкий | около 13 лет назад | ||
CVE-2013-4113 ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function. | CVSS2: 6.8 | 5% Низкий | около 13 лет назад | |
CVE-2013-4636 The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object. | CVSS2: 4.3 | 2% Низкий | около 13 лет назад | |
CVE-2013-4636 The mget function in libmagic/softmagic.c in the Fileinfo component in ... | CVSS2: 4.3 | 2% Низкий | около 13 лет назад | |
CVE-2013-4635 Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function. | CVSS2: 5 | 4% Низкий | около 13 лет назад | |
CVE-2013-4635 Integer overflow in the SdnToJewish function in jewish.c in the Calend ... | CVSS2: 5 | 4% Низкий | около 13 лет назад | |
CVE-2013-4635 Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function. | CVSS2: 5 | 4% Низкий | около 13 лет назад |
Уязвимостей на страницу