Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 889

nvd логотип

CVE-2006-7243

около 15 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-7243

около 15 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might a ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4698

около 15 лет назад

Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstext function.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4697

около 15 лет назад

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4699

около 15 лет назад

The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an incomplete output array, and possibly bypass spam detection or have unspecified other impact, via a crafted Subject header in an e-mail message, as demonstrated by the ks_c_5601-1987 character set.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-7243

около 15 лет назад

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4700

около 15 лет назад

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

CVSS2: 6.8
EPSS: Низкий
fstec логотип

BDU:2022-02605

около 15 лет назад

Уязвимость функции iconv_mime_decode_headers расширения Iconv интерпретатора языка программирования PHP, позволяющая нарушителю вызвать формирование неполного выходного массива, обойти защиту от спама или оказать иное воздействие на систему

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2022-02597

около 15 лет назад

Уязвимость функции file_exists интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2010-4645

около 15 лет назад

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-7243

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

CVSS2: 5
2%
Низкий
около 15 лет назад
debian логотип
CVE-2006-7243

PHP before 5.3.4 accepts the \0 character in a pathname, which might a ...

CVSS2: 5
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4698

Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstext function.

CVSS2: 5
9%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4697

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

CVSS2: 6.8
1%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4699

The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an incomplete output array, and possibly bypass spam detection or have unspecified other impact, via a crafted Subject header in an e-mail message, as demonstrated by the ks_c_5601-1987 character set.

CVSS2: 5
0%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2006-7243

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argument to the file_exists function.

CVSS2: 5
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2010-4700

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injection attacks via crafted input that had been properly handled in earlier PHP versions.

CVSS2: 6.8
0%
Низкий
около 15 лет назад
fstec логотип
BDU:2022-02605

Уязвимость функции iconv_mime_decode_headers расширения Iconv интерпретатора языка программирования PHP, позволяющая нарушителю вызвать формирование неполного выходного массива, обойти защиту от спама или оказать иное воздействие на систему

CVSS3: 5.3
0%
Низкий
около 15 лет назад
fstec логотип
BDU:2022-02597

Уязвимость функции file_exists интерпретатора языка программирования PHP, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 3.7
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-4645

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

CVSS2: 5
19%
Средний
около 15 лет назад

Уязвимостей на страницу


Поделиться