Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

redhat логотип

CVE-2011-4566

больше 14 лет назад

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 5.8
EPSS: Средний
redhat логотип

CVE-2011-3379

больше 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2011-3268

больше 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2011-3268

больше 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows conte ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2011-3267

больше 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-3267

больше 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, w ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3268

больше 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2011-3267

больше 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3189

больше 14 лет назад

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-3189

больше 14 лет назад

The crypt function in PHP 5.3.7, when the MD5 hash type is used, retur ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2011-4566

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 5.8
44%
Средний
больше 14 лет назад
redhat логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 5.1
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
16%
Средний
больше 14 лет назад
debian логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows conte ...

CVSS2: 10
16%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, w ...

CVSS2: 5
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
16%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-3189

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4.3
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-3189

The crypt function in PHP 5.3.7, when the MD5 hash type is used, retur ...

CVSS2: 4.3
1%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться