Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.18.28.38.4202120222023202420252026202720282029

Недавние уязвимости PHP

Количество 3 756

debian логотип

CVE-2003-0863

больше 21 года назад

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2003-0860

больше 21 года назад

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown a ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0442

почти 22 года назад

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2003-0442

почти 22 года назад

Cross-site scripting (XSS) vulnerability in the transparent SID suppor ...

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2003-1303

около 22 лет назад

Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.

EPSS: Низкий
redhat логотип

CVE-2003-0442

около 22 лет назад

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

EPSS: Средний
nvd логотип

CVE-2003-0172

около 22 лет назад

Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2003-0166

около 22 лет назад

Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2003-0172

около 22 лет назад

Buffer overflow in openlog function for PHP 4.3.1 on Windows operating ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2003-0166

около 22 лет назад

Integer signedness error in emalloc() function for PHP before 4.3.2 al ...

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2003-0863

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...

CVSS2: 7.5
3%
Низкий
больше 21 года назад
debian логотип
CVE-2003-0860

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown a ...

CVSS2: 10
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-0442

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

CVSS2: 4.3
52%
Средний
почти 22 года назад
debian логотип
CVE-2003-0442

Cross-site scripting (XSS) vulnerability in the transparent SID suppor ...

CVSS2: 4.3
52%
Средний
почти 22 года назад
redhat логотип
CVE-2003-1303

Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.

1%
Низкий
около 22 лет назад
redhat логотип
CVE-2003-0442

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

52%
Средний
около 22 лет назад
nvd логотип
CVE-2003-0172

Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.

CVSS2: 7.5
23%
Средний
около 22 лет назад
nvd логотип
CVE-2003-0166

Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.

CVSS2: 7.5
27%
Средний
около 22 лет назад
debian логотип
CVE-2003-0172

Buffer overflow in openlog function for PHP 4.3.1 on Windows operating ...

CVSS2: 7.5
23%
Средний
около 22 лет назад
debian логотип
CVE-2003-0166

Integer signedness error in emalloc() function for PHP before 4.3.2 al ...

CVSS2: 7.5
27%
Средний
около 22 лет назад

Уязвимостей на страницу


Поделиться