Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

fstec логотип

BDU:2022-02621

около 14 лет назад

Уязвимость функции phar_parse_tarfile интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 5.6
EPSS: Средний
debian логотип

CVE-2012-2143

около 14 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-REL ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-2143

около 14 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-2143

около 14 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
EPSS: Низкий
fstec логотип

BDU:2022-02629

около 14 лет назад

Уязвимость функции crypt_des операционной системы FreeBSD, позволяющая нарушителю повысить свои привилегии

CVSS3: 3.7
EPSS: Низкий
oracle-oval логотип

ELSA-2012-1036

около 14 лет назад

ELSA-2012-1036: postgresql security update (MODERATE)

EPSS: Низкий
redhat логотип

CVE-2012-3450

больше 14 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2012-2143

больше 14 лет назад

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-1172

больше 14 лет назад

The file-upload implementation in rfc1867.c in PHP before 5.4.0 does n ...

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2012-1172

больше 14 лет назад

The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket) characters in name values, which makes it easier for remote attackers to cause a denial of service (malformed $_FILES indexes) or conduct directory traversal attacks during multi-file uploads by leveraging a script that lacks its own filename restrictions.

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2022-02621

Уязвимость функции phar_parse_tarfile интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 5.6
42%
Средний
около 14 лет назад
debian логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-REL ...

CVSS2: 4.3
6%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
6%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4.3
6%
Низкий
около 14 лет назад
fstec логотип
BDU:2022-02629

Уязвимость функции crypt_des операционной системы FreeBSD, позволяющая нарушителю повысить свои привилегии

CVSS3: 3.7
6%
Низкий
около 14 лет назад
oracle-oval логотип
ELSA-2012-1036

ELSA-2012-1036: postgresql security update (MODERATE)

6%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 6.8
11%
Средний
больше 14 лет назад
redhat логотип
CVE-2012-2143

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.

CVSS2: 4
6%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-1172

The file-upload implementation in rfc1867.c in PHP before 5.4.0 does n ...

CVSS2: 5.8
6%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-1172

The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket) characters in name values, which makes it easier for remote attackers to cause a denial of service (malformed $_FILES indexes) or conduct directory traversal attacks during multi-file uploads by leveraging a script that lacks its own filename restrictions.

CVSS2: 5.8
6%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться