Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

ubuntu логотип

CVE-2006-7205

больше 18 лет назад

The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-7204

больше 18 лет назад

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2006-7204

больше 18 лет назад

The imap_body function in PHP before 4.4.4 does not implement safemode ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-7204

больше 18 лет назад

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2007-2748

больше 18 лет назад

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-2748

больше 18 лет назад

The substr_count function in PHP 5.2.1 and earlier allows context-depe ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-2748

больше 18 лет назад

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-2728

больше 18 лет назад

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-2727

больше 18 лет назад

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-2728

больше 18 лет назад

The soap extension in PHP calls php_rand_r with an uninitialized seed ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2006-7205

The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value.

CVSS2: 5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-7204

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

CVSS2: 2.1
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-7204

The imap_body function in PHP before 4.4.4 does not implement safemode ...

CVSS2: 2.1
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-7204

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

CVSS2: 2.1
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2748

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2748

The substr_count function in PHP 5.2.1 and earlier allows context-depe ...

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2748

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

CVSS2: 5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2727

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed ...

CVSS2: 5
1%
Низкий
больше 18 лет назад

Уязвимостей на страницу


Поделиться