Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 4 009

debian логотип

CVE-2004-1392

больше 21 года назад

PHP 4.0 with cURL functions allows remote attackers to bypass the open ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2004-1392

больше 21 года назад

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-1392

больше 21 года назад

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2004-1018

почти 22 года назад

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

EPSS: Средний
redhat логотип

CVE-2004-1065

почти 22 года назад

Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.

EPSS: Средний
redhat логотип

CVE-2004-1019

почти 22 года назад

The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.

EPSS: Низкий
redhat логотип

CVE-2004-1392

почти 22 года назад

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

EPSS: Средний
debian логотип

CVE-2004-0959

почти 22 года назад

rfc1867.c in PHP before 5.0.2 allows local users to upload files to ar ...

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2004-0958

почти 22 года назад

php_variables.c in PHP before 5.0.2 allows remote attackers to read se ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0958

почти 22 года назад

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2004-1392

PHP 4.0 with cURL functions allows remote attackers to bypass the open ...

CVSS2: 5
11%
Средний
больше 21 года назад
ubuntu логотип
CVE-2004-1392

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

CVSS2: 5
11%
Средний
больше 21 года назад
nvd логотип
CVE-2004-1392

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

CVSS2: 5
11%
Средний
больше 21 года назад
redhat логотип
CVE-2004-1018

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

16%
Средний
почти 22 года назад
redhat логотип
CVE-2004-1065

Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.

10%
Средний
почти 22 года назад
redhat логотип
CVE-2004-1019

The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.

8%
Низкий
почти 22 года назад
redhat логотип
CVE-2004-1392

PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

11%
Средний
почти 22 года назад
debian логотип
CVE-2004-0959

rfc1867.c in PHP before 5.0.2 allows local users to upload files to ar ...

CVSS2: 2.1
1%
Низкий
почти 22 года назад
debian логотип
CVE-2004-0958

php_variables.c in PHP before 5.0.2 allows remote attackers to read se ...

CVSS2: 5
10%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0958

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

CVSS2: 5
10%
Низкий
почти 22 года назад

Уязвимостей на страницу


Поделиться