Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 768

nvd логотип

CVE-2006-4485

почти 19 лет назад

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2006-4482

почти 19 лет назад

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2006-4484

почти 19 лет назад

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-4483

почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2006-4486

почти 19 лет назад

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-4485

почти 19 лет назад

The stripos function in PHP before 5.1.5 has unknown impact and attack ...

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2006-4484

почти 19 лет назад

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-4482

почти 19 лет назад

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wor ...

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2006-4481

почти 19 лет назад

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 ...

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2006-4483

почти 19 лет назад

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/str ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-4485

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

CVSS2: 10
2%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-4482

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.

CVSS2: 9.3
4%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-4484

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

CVSS2: 2.6
3%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-4483

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

CVSS2: 9.3
2%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-4486

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

CVSS2: 2.6
2%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4485

The stripos function in PHP before 5.1.5 has unknown impact and attack ...

CVSS2: 10
2%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4484

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in ...

CVSS2: 2.6
3%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4482

Multiple heap-based buffer overflows in the (1) str_repeat and (2) wor ...

CVSS2: 9.3
4%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4481

The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 ...

CVSS2: 7.2
0%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4483

The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/str ...

CVSS2: 9.3
2%
Низкий
почти 19 лет назад

Уязвимостей на страницу


Поделиться