PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 984
ELSA-2011-1378
ELSA-2011-1378: postgresql84 security update (MODERATE)
CVE-2011-3379
The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.
CVE-2011-3268
Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.
CVE-2011-3268
Buffer overflow in the crypt function in PHP before 5.3.7 allows conte ...
CVE-2011-3267
PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.
CVE-2011-3267
PHP before 5.3.7 does not properly implement the error_log function, w ...
CVE-2011-3267
PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.
CVE-2011-3268
Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.
CVE-2011-3189
The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.
CVE-2011-3189
The crypt function in PHP 5.3.7, when the MD5 hash type is used, retur ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
ELSA-2011-1378 ELSA-2011-1378: postgresql84 security update (MODERATE) | 5% Низкий | почти 15 лет назад | ||
CVE-2011-3379 The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders. | CVSS2: 5.1 | 5% Низкий | почти 15 лет назад | |
CVE-2011-3268 Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483. | CVSS2: 10 | 6% Низкий | почти 15 лет назад | |
CVE-2011-3268 Buffer overflow in the crypt function in PHP before 5.3.7 allows conte ... | CVSS2: 10 | 6% Низкий | почти 15 лет назад | |
CVE-2011-3267 PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors. | CVSS2: 5 | 3% Низкий | почти 15 лет назад | |
CVE-2011-3267 PHP before 5.3.7 does not properly implement the error_log function, w ... | CVSS2: 5 | 3% Низкий | почти 15 лет назад | |
CVE-2011-3267 PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors. | CVSS2: 5 | 3% Низкий | почти 15 лет назад | |
CVE-2011-3268 Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483. | CVSS2: 10 | 6% Низкий | почти 15 лет назад | |
CVE-2011-3189 The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483. | CVSS2: 4.3 | 4% Низкий | почти 15 лет назад | |
CVE-2011-3189 The crypt function in PHP 5.3.7, when the MD5 hash type is used, retur ... | CVSS2: 4.3 | 4% Низкий | почти 15 лет назад |
Уязвимостей на страницу