Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 768

ubuntu логотип

CVE-2007-1649

больше 18 лет назад

PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-1581

больше 18 лет назад

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2007-1583

больше 18 лет назад

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2007-1582

больше 18 лет назад

The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1584

больше 18 лет назад

Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1584

больше 18 лет назад

Buffer underflow in the header function in PHP 5.2.0 allows context-de ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1581

больше 18 лет назад

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependen ...

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2007-1582

больше 18 лет назад

The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1583

больше 18 лет назад

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through ...

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2007-1583

больше 18 лет назад

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

CVSS2: 6.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2007-1649

PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

CVSS2: 7.8
7%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1581

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.

CVSS2: 9.3
8%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1583

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

CVSS2: 6.8
14%
Средний
больше 18 лет назад
nvd логотип
CVE-2007-1582

The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.

CVSS2: 6.8
2%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1584

Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.

CVSS2: 6.8
3%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1584

Buffer underflow in the header function in PHP 5.2.0 allows context-de ...

CVSS2: 6.8
3%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1581

The resource system in PHP 5.0.0 through 5.2.1 allows context-dependen ...

CVSS2: 9.3
8%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1582

The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 ...

CVSS2: 6.8
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1583

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through ...

CVSS2: 6.8
14%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-1583

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

CVSS2: 6.8
14%
Средний
больше 18 лет назад

Уязвимостей на страницу


Поделиться