PHP — популярный язык сценариев общего назначения, особенно подходящий для веб-разработки.
Релизный цикл, информация об уязвимостях
График релизов
Количество 3 868
CVE-2003-0861
Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.
CVE-2003-0863
The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...
CVE-2003-0860
Buffer overflows in PHP before 4.3.3 have unknown impact and unknown a ...
CVE-2003-0861
Integer overflows in (1) base64_encode and (2) the GD library for PHP ...
CVE-2003-0442
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
CVE-2003-0442
Cross-site scripting (XSS) vulnerability in the transparent SID suppor ...
CVE-2003-1303
Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.
CVE-2003-0442
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
CVE-2003-0172
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.
CVE-2003-0166
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2003-0861 Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors. | CVSS2: 10 | 1% Низкий | около 22 лет назад | |
CVE-2003-0863 The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ... | CVSS2: 7.5 | 3% Низкий | около 22 лет назад | |
CVE-2003-0860 Buffer overflows in PHP before 4.3.3 have unknown impact and unknown a ... | CVSS2: 10 | 0% Низкий | около 22 лет назад | |
CVE-2003-0861 Integer overflows in (1) base64_encode and (2) the GD library for PHP ... | CVSS2: 10 | 1% Низкий | около 22 лет назад | |
CVE-2003-0442 Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter. | CVSS2: 4.3 | 52% Средний | больше 22 лет назад | |
CVE-2003-0442 Cross-site scripting (XSS) vulnerability in the transparent SID suppor ... | CVSS2: 4.3 | 52% Средний | больше 22 лет назад | |
CVE-2003-1303 Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header. | 1% Низкий | больше 22 лет назад | ||
CVE-2003-0442 Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter. | 52% Средний | больше 22 лет назад | ||
CVE-2003-0172 Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument. | CVSS2: 7.5 | 22% Средний | больше 22 лет назад | |
CVE-2003-0166 Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions. | CVSS2: 7.5 | 27% Средний | больше 22 лет назад |
Уязвимостей на страницу