PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 4 009
BDU:2024-05844
Уязвимость интерпретатора языка программирования PHP, связанная с неправильной проверкой входных данных, позволяющая нарушителю устанавливать в браузере стандартный небезопасный файл cookie
ELSA-2022-6158
ELSA-2022-6158: php:7.4 security update (MODERATE)
RLSA-2022:6158
Moderate: php:7.4 security update
RLSA-2022:5904
Important: php security update
ELSA-2022-5904
ELSA-2022-5904: php security update (IMPORTANT)
GHSA-2c24-m9rj-gq8m
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
CVE-2022-31627
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as fi ...
CVE-2022-31627
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
CVE-2022-31627
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
BDU:2024-07319
Уязвимость языка программирования PHP, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2024-05844 Уязвимость интерпретатора языка программирования PHP, связанная с неправильной проверкой входных данных, позволяющая нарушителю устанавливать в браузере стандартный небезопасный файл cookie | CVSS3: 6.5 | 49% Средний | почти 4 года назад | |
ELSA-2022-6158 ELSA-2022-6158: php:7.4 security update (MODERATE) | 4% Низкий | около 4 лет назад | ||
RLSA-2022:6158 Moderate: php:7.4 security update | 4% Низкий | около 4 лет назад | ||
RLSA-2022:5904 Important: php security update | 58% Средний | около 4 лет назад | ||
ELSA-2022-5904 ELSA-2022-5904: php security update (IMPORTANT) | 58% Средний | около 4 лет назад | ||
GHSA-2c24-m9rj-gq8m In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
CVE-2022-31627 In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as fi ... | CVSS3: 7.7 | 2% Низкий | около 4 лет назад | |
CVE-2022-31627 In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption. | CVSS3: 7.7 | 2% Низкий | около 4 лет назад | |
CVE-2022-31627 In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption. | CVSS3: 7.7 | 2% Низкий | около 4 лет назад | |
BDU:2024-07319 Уязвимость языка программирования PHP, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу