Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"
PHP

PHPпопулярный язык сценариев общего назначения, особенно подходящий для веб-разработки.

Релизный цикл, информация об уязвимостях

Продукт: PHP
Вендор: php

График релизов

8.28.38.48.5202220232024202520262027202820292030

Недавние уязвимости PHP

Количество 3 883

ubuntu логотип

CVE-2024-8929

около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2024-8929

около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2024-8932

около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-8932

около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-8932

около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2024-8932

около 1 года назад

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h35g-vwh6-m678

около 1 года назад

[Mysqlnd] Leak partial content of the heap through heap buffer over-read

EPSS: Низкий
github логотип

GHSA-g665-fm4p-vhff

около 1 года назад

OOB access in ldap_escape

EPSS: Низкий
github логотип

GHSA-c5f2-jwm7-mmq2

около 1 года назад

Configuring a proxy in a stream context might allow for CRLF injection in URIs

EPSS: Низкий
github логотип

GHSA-5hqh-c84r-qjcv

около 1 года назад

Integer overflow in the firebird and dblib quoters causing OOB writes

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-8929

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-8929

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

CVSS3: 5.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before ...

CVSS3: 9.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 9.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-8932

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-h35g-vwh6-m678

[Mysqlnd] Leak partial content of the heap through heap buffer over-read

0%
Низкий
около 1 года назад
github логотип
GHSA-g665-fm4p-vhff

OOB access in ldap_escape

0%
Низкий
около 1 года назад
github логотип
GHSA-c5f2-jwm7-mmq2

Configuring a proxy in a stream context might allow for CRLF injection in URIs

0%
Низкий
около 1 года назад
github логотип
GHSA-5hqh-c84r-qjcv

Integer overflow in the firebird and dblib quoters causing OOB writes

0%
Низкий
около 1 года назад

Уязвимостей на страницу


Поделиться