PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 883
CVE-2007-1375
Integer overflow in the substr_compare function in PHP 5.2.1 and earli ...
CVE-2007-1376
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x s ...
CVE-2007-1381
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10 ...
CVE-2007-1380
The php_binary serialization handler in the session extension in PHP b ...
CVE-2007-1379
The ovrimos_close function in the Ovrimos extension for PHP before 4.4 ...
CVE-2007-1378
The ovrimos_longreadlen function in the Ovrimos extension for PHP befo ...
CVE-2007-1378
The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.
CVE-2007-1381
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.
CVE-2007-1376
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
CVE-2007-1375
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2007-1375 Integer overflow in the substr_compare function in PHP 5.2.1 and earli ... | CVSS2: 5 | 15% Средний | почти 19 лет назад | |
CVE-2007-1376 The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x s ... | CVSS2: 7.5 | 14% Средний | почти 19 лет назад | |
CVE-2007-1381 The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10 ... | CVSS2: 7.6 | 5% Низкий | почти 19 лет назад | |
CVE-2007-1380 The php_binary serialization handler in the session extension in PHP b ... | CVSS2: 5 | 13% Средний | почти 19 лет назад | |
CVE-2007-1379 The ovrimos_close function in the Ovrimos extension for PHP before 4.4 ... | CVSS2: 5.1 | 1% Низкий | почти 19 лет назад | |
CVE-2007-1378 The ovrimos_longreadlen function in the Ovrimos extension for PHP befo ... | CVSS2: 5.1 | 1% Низкий | почти 19 лет назад | |
CVE-2007-1378 The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments. | CVSS2: 5.1 | 1% Низкий | почти 19 лет назад | |
CVE-2007-1381 The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow. | CVSS2: 7.6 | 5% Низкий | почти 19 лет назад | |
CVE-2007-1376 The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource. | CVSS2: 7.5 | 14% Средний | почти 19 лет назад | |
CVE-2007-1375 Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991. | CVSS2: 5 | 15% Средний | почти 19 лет назад |
Уязвимостей на страницу