PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 889
CVE-2007-1376
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
CVE-2007-1383
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.
CVE-2007-1381
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.
CVE-2007-1380
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.
CVE-2007-1375
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.
CVE-2007-1378
The ovrimos_longreadlen function in the Ovrimos extension for PHP befo ...
CVE-2007-1379
The ovrimos_close function in the Ovrimos extension for PHP before 4.4 ...
CVE-2007-1383
Integer overflow in the 16 bit variable reference counter in PHP 4 all ...
CVE-2007-1375
Integer overflow in the substr_compare function in PHP 5.2.1 and earli ...
CVE-2007-1376
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x s ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2007-1376 The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource. | CVSS2: 7.5 | 15% Средний | около 19 лет назад | |
CVE-2007-1383 Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286. | CVSS3: 9.8 | 3% Низкий | около 19 лет назад | |
CVE-2007-1381 The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow. | CVSS2: 7.6 | 5% Низкий | около 19 лет назад | |
CVE-2007-1380 The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read. | CVSS2: 5 | 14% Средний | около 19 лет назад | |
CVE-2007-1375 Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991. | CVSS2: 5 | 17% Средний | около 19 лет назад | |
CVE-2007-1378 The ovrimos_longreadlen function in the Ovrimos extension for PHP befo ... | CVSS2: 5.1 | 1% Низкий | около 19 лет назад | |
CVE-2007-1379 The ovrimos_close function in the Ovrimos extension for PHP before 4.4 ... | CVSS2: 5.1 | 1% Низкий | около 19 лет назад | |
CVE-2007-1383 Integer overflow in the 16 bit variable reference counter in PHP 4 all ... | CVSS3: 9.8 | 3% Низкий | около 19 лет назад | |
CVE-2007-1375 Integer overflow in the substr_compare function in PHP 5.2.1 and earli ... | CVSS2: 5 | 17% Средний | около 19 лет назад | |
CVE-2007-1376 The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x s ... | CVSS2: 7.5 | 15% Средний | около 19 лет назад |
Уязвимостей на страницу