Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 863

debian логотип

CVE-2007-2728

больше 18 лет назад

The soap extension in PHP calls php_rand_r with an uninitialized seed ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-2727

больше 18 лет назад

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2007-2728

больше 18 лет назад

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1864

больше 18 лет назад

Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-2509

больше 18 лет назад

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2007-2510

больше 18 лет назад

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2007-2511

больше 18 лет назад

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2007-2510

больше 18 лет назад

Buffer overflow in the make_http_soap_request function in PHP before 5 ...

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2007-2509

больше 18 лет назад

CRLF injection vulnerability in the ftp_putcmd function in PHP before ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-2511

больше 18 лет назад

Buffer overflow in the user_filter_factory_create function in PHP befo ...

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed ...

CVSS2: 5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2727

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

CVSS2: 5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1864

Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.

CVSS2: 7.5
5%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2509

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

CVSS2: 2.6
4%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2510

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

CVSS2: 5.1
3%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2511

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

CVSS2: 7.2
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2510

Buffer overflow in the make_http_soap_request function in PHP before 5 ...

CVSS2: 5.1
3%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2509

CRLF injection vulnerability in the ftp_putcmd function in PHP before ...

CVSS2: 2.6
4%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2511

Buffer overflow in the user_filter_factory_create function in PHP befo ...

CVSS2: 7.2
0%
Низкий
больше 18 лет назад

Уязвимостей на страницу


Поделиться