Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

ubuntu логотип

CVE-2007-1379

почти 19 лет назад

The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2007-1378

почти 19 лет назад

The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2007-1375

почти 19 лет назад

Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2007-1001

почти 19 лет назад

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

EPSS: Средний
nvd логотип

CVE-2007-1285

почти 19 лет назад

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1286

почти 19 лет назад

Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.

CVSS2: 6.8
EPSS: Высокий
nvd логотип

CVE-2007-1287

почти 19 лет назад

A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2007-1285

почти 19 лет назад

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows ...

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2007-1286

почти 19 лет назад

Integer overflow in PHP 4.4.4 and earlier allows remote context-depend ...

CVSS2: 6.8
EPSS: Высокий
debian логотип

CVE-2007-1287

почти 19 лет назад

A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and ...

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2007-1379

The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.

CVSS2: 5.1
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-1378

The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.

CVSS2: 5.1
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-1375

Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.

CVSS2: 5
15%
Средний
почти 19 лет назад
redhat логотип
CVE-2007-1001

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

10%
Средний
почти 19 лет назад
nvd логотип
CVE-2007-1285

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

CVSS3: 7.5
9%
Низкий
почти 19 лет назад
nvd логотип
CVE-2007-1286

Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.

CVSS2: 6.8
87%
Высокий
почти 19 лет назад
nvd логотип
CVE-2007-1287

A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as originally fixed for CVE-2005-3388.

CVSS2: 4.3
23%
Средний
почти 19 лет назад
debian логотип
CVE-2007-1285

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows ...

CVSS3: 7.5
9%
Низкий
почти 19 лет назад
debian логотип
CVE-2007-1286

Integer overflow in PHP 4.4.4 and earlier allows remote context-depend ...

CVSS2: 6.8
87%
Высокий
почти 19 лет назад
debian логотип
CVE-2007-1287

A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and ...

CVSS2: 4.3
23%
Средний
почти 19 лет назад

Уязвимостей на страницу


Поделиться