Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 867

nvd логотип

CVE-2007-1001

больше 18 лет назад

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2007-1001

больше 18 лет назад

Multiple integer overflows in the (1) createwbmp and (2) readwbmp func ...

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2007-1001

больше 18 лет назад

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2007-1835

больше 18 лет назад

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2007-1835

больше 18 лет назад

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session ...

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2007-1835

больше 18 лет назад

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2007-1825

больше 18 лет назад

Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1824

больше 18 лет назад

Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the '.' character.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2007-1825

больше 18 лет назад

Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2. ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-1824

больше 18 лет назад

Buffer overflow in the php_stream_filter_create function in PHP 5 befo ...

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2007-1001

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

CVSS2: 6.8
13%
Средний
больше 18 лет назад
debian логотип
CVE-2007-1001

Multiple integer overflows in the (1) createwbmp and (2) readwbmp func ...

CVSS2: 6.8
13%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-1001

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

CVSS2: 6.8
13%
Средний
больше 18 лет назад
nvd логотип
CVE-2007-1835

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.

CVSS2: 4.6
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1835

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session ...

CVSS2: 4.6
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1835

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.

CVSS2: 4.6
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1825

Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue might be subsumed by CVE-2007-0906.3.

CVSS2: 7.5
6%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1824

Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the '.' character.

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1825

Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2. ...

CVSS2: 7.5
6%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1824

Buffer overflow in the php_stream_filter_create function in PHP 5 befo ...

CVSS2: 5.1
2%
Низкий
больше 18 лет назад

Уязвимостей на страницу


Поделиться