Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 889

redhat логотип

CVE-2009-3293

больше 16 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-7068

больше 16 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2008-7068

больше 16 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2008-7068

больше 16 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2008-7002

больше 16 лет назад

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2008-7002

больше 16 лет назад

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir ...

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2008-7002

больше 16 лет назад

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2009-2687

больше 16 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2009-2687

больше 16 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 al ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2009-2687

больше 16 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 4.3
2%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent ...

CVSS2: 6.4
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-7002

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

CVSS2: 7.2
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-7002

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir ...

CVSS2: 7.2
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-7002

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

CVSS2: 7.2
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
12%
Средний
больше 16 лет назад
debian логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 al ...

CVSS2: 4.3
12%
Средний
больше 16 лет назад
ubuntu логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
12%
Средний
больше 16 лет назад

Уязвимостей на страницу


Поделиться