Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 58

Количество 58

rocky логотип

RLSA-2022:7628

больше 3 лет назад

Moderate: php:7.4 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7628

больше 3 лет назад

ELSA-2022-7628: php:7.4 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-21707

больше 4 лет назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2021-21707

больше 4 лет назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2021-21707

больше 4 лет назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Средний
msrc логотип

CVE-2021-21707

10 месяцев назад

Special characters break path parsing in XML functions

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2021-21707

больше 4 лет назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below ...

CVSS3: 5.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2022:3997-1

больше 3 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3927-1

больше 4 лет назад

Security update for php74

EPSS: Средний
github логотип

GHSA-qh78-qfw9-93x9

больше 4 лет назад

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
EPSS: Средний
fstec логотип

BDU:2022-02394

больше 4 лет назад

Уязвимость функции simplexml_load_file() интерпретатора PHP , позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2022:4069-1

больше 3 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4068-1

больше 3 лет назад

Security update for php74

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3943-1

больше 4 лет назад

Recommended update for php7

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1570-1

больше 4 лет назад

Recommended update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3943-1

больше 4 лет назад

Recommended update for php7

EPSS: Низкий
ubuntu логотип

CVE-2021-32610

около 5 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
EPSS: Высокий
redhat логотип

CVE-2021-32610

около 5 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.4
EPSS: Высокий
nvd логотип

CVE-2021-32610

около 5 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
EPSS: Высокий
debian логотип

CVE-2021-32610

около 5 лет назад

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ...

CVSS3: 7.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2022:7628

Moderate: php:7.4 security, bug fix, and enhancement update

больше 3 лет назад
oracle-oval логотип
ELSA-2022-7628

ELSA-2022-7628: php:7.4 security, bug fix, and enhancement update (MODERATE)

больше 3 лет назад
ubuntu логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
26%
Средний
больше 4 лет назад
redhat логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
26%
Средний
больше 4 лет назад
nvd логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
26%
Средний
больше 4 лет назад
msrc логотип
CVE-2021-21707

Special characters break path parsing in XML functions

CVSS3: 5.3
26%
Средний
10 месяцев назад
debian логотип
CVE-2021-21707

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below ...

CVSS3: 5.3
26%
Средний
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:3997-1

Security update for php7

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:3927-1

Security update for php74

26%
Средний
больше 4 лет назад
github логотип
GHSA-qh78-qfw9-93x9

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.

CVSS3: 5.3
26%
Средний
больше 4 лет назад
fstec логотип
BDU:2022-02394

Уязвимость функции simplexml_load_file() интерпретатора PHP , позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
26%
Средний
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:4069-1

Security update for php7

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:4068-1

Security update for php74

больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3943-1

Recommended update for php7

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1570-1

Recommended update for php7

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3943-1

Recommended update for php7

больше 4 лет назад
ubuntu логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
73%
Высокий
около 5 лет назад
redhat логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.4
73%
Высокий
около 5 лет назад
nvd логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS3: 7.1
73%
Высокий
около 5 лет назад
debian логотип
CVE-2021-32610

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of ...

CVSS3: 7.1
73%
Высокий
около 5 лет назад

Уязвимостей на страницу