Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 010

nvd логотип

CVE-2007-4662

около 19 лет назад

Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-4657

около 19 лет назад

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-4661

около 19 лет назад

The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-4659

около 19 лет назад

The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-4652

около 19 лет назад

The session extension in PHP before 5.2.4 might allow local users to b ...

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2007-4652

около 19 лет назад

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2007-4652

около 19 лет назад

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

CVSS2: 4.4
EPSS: Низкий
debian логотип

CVE-2007-3998

около 19 лет назад

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, d ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-3997

около 19 лет назад

The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2007-3996

около 19 лет назад

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote a ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2007-4662

Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors.

CVSS2: 7.5
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-4657

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

CVSS2: 7.5
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-4661

The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.

CVSS2: 7.5
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-4659

The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.

CVSS2: 7.5
3%
Низкий
около 19 лет назад
debian логотип
CVE-2007-4652

The session extension in PHP before 5.2.4 might allow local users to b ...

CVSS2: 4.4
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-4652

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

CVSS2: 4.4
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-4652

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

CVSS2: 4.4
1%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3998

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, d ...

CVSS2: 5
3%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3997

The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP ...

CVSS2: 7.5
14%
Средний
около 19 лет назад
debian логотип
CVE-2007-3996

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote a ...

CVSS2: 6.8
4%
Низкий
около 19 лет назад

Уязвимостей на страницу


Поделиться