Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 984

redhat логотип

CVE-2010-3870

почти 17 лет назад

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2009-3294

почти 17 лет назад

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-3294

почти 17 лет назад

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5 ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3292

почти 17 лет назад

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3292

почти 17 лет назад

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1 ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3291

почти 17 лет назад

The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3291

почти 17 лет назад

The php_openssl_apply_verification_policy function in PHP before 5.2.1 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2010-3870

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

CVSS2: 4.3
11%
Средний
почти 17 лет назад
nvd логотип
CVE-2009-3294

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

CVSS2: 5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3294

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5 ...

CVSS2: 5
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP ...

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3292

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3292

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1 ...

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3291

The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3291

The php_openssl_apply_verification_policy function in PHP before 5.2.1 ...

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
3%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться