Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

debian логотип

CVE-2007-1521

почти 19 лет назад

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, a ...

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2007-1521

почти 19 лет назад

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2007-1522

почти 19 лет назад

Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2007-1583

почти 19 лет назад

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

EPSS: Средний
nvd логотип

CVE-2007-1484

почти 19 лет назад

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2007-1475

почти 19 лет назад

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
EPSS: Низкий
debian логотип

CVE-2007-1475

почти 19 лет назад

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconn ...

CVSS2: 5.4
EPSS: Низкий
debian логотип

CVE-2007-1484

почти 19 лет назад

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x ...

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2007-1475

почти 19 лет назад

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2007-1484

почти 19 лет назад

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2007-1521

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, a ...

CVSS2: 6.8
15%
Средний
почти 19 лет назад
ubuntu логотип
CVE-2007-1521

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

CVSS2: 6.8
15%
Средний
почти 19 лет назад
ubuntu логотип
CVE-2007-1522

Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

CVSS2: 6.8
8%
Низкий
почти 19 лет назад
redhat логотип
CVE-2007-1583

The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

21%
Средний
почти 19 лет назад
nvd логотип
CVE-2007-1484

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
0%
Низкий
почти 19 лет назад
nvd логотип
CVE-2007-1475

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
2%
Низкий
почти 19 лет назад
debian логотип
CVE-2007-1475

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconn ...

CVSS2: 5.4
2%
Низкий
почти 19 лет назад
debian логотип
CVE-2007-1484

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x ...

CVSS2: 4.6
0%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-1475

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
2%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-1484

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
0%
Низкий
почти 19 лет назад

Уязвимостей на страницу


Поделиться