Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

ubuntu логотип

CVE-2009-2687

около 17 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2011-1471

около 17 лет назад

Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2009-4018

около 17 лет назад

The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.

CVSS2: 3.3
EPSS: Средний
redhat логотип

CVE-2009-2687

больше 17 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2009-1272

больше 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x befo ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-1272

больше 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-1271

больше 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-1271

больше 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1271

больше 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1272

больше 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
4%
Низкий
около 17 лет назад
redhat логотип
CVE-2011-1471

Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

CVSS2: 4.3
13%
Средний
около 17 лет назад
redhat логотип
CVE-2009-4018

The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.

CVSS2: 3.3
11%
Средний
около 17 лет назад
redhat логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 5.8
4%
Низкий
больше 17 лет назад
debian логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x befo ...

CVSS2: 5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
2%
Низкий
больше 17 лет назад
debian логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before ...

CVSS2: 5
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
2%
Низкий
больше 17 лет назад

Уязвимостей на страницу


Поделиться