Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 883

Количество 3 883

debian логотип

CVE-2014-4698

больше 11 лет назад

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL compone ...

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2014-4670

больше 11 лет назад

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2014-4670

больше 11 лет назад

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-4670

больше 11 лет назад

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2014-4670

больше 11 лет назад

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL compon ...

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2014-4049

больше 11 лет назад

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

CVSS2: 5.1
EPSS: Средний
redhat логотип

CVE-2014-4049

больше 11 лет назад

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2014-4049

больше 11 лет назад

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

CVSS2: 5.1
EPSS: Средний
debian логотип

CVE-2014-4049

больше 11 лет назад

Heap-based buffer overflow in the php_parserr function in ext/standard ...

CVSS2: 5.1
EPSS: Средний
ubuntu логотип

CVE-2014-3981

больше 11 лет назад

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS2: 3.3
EPSS: Низкий
redhat логотип

CVE-2014-3981

больше 11 лет назад

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-3981

больше 11 лет назад

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS2: 3.3
EPSS: Низкий
debian логотип

CVE-2014-3981

больше 11 лет назад

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlie ...

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2014-3710

больше 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2014-3710

больше 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2014-3710

больше 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-3710

больше 11 лет назад

The donote function in readelf.c in file through 5.20, as used in the ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-3670

больше 11 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2014-3670

больше 11 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2014-3670

больше 11 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2014-4698

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL compone ...

CVSS2: 4.6
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-4670

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

CVSS2: 4.6
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-4670

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-4670

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

CVSS2: 4.6
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-4670

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL compon ...

CVSS2: 4.6
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-4049

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

CVSS2: 5.1
18%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-4049

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

CVSS2: 5.1
18%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-4049

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.

CVSS2: 5.1
18%
Средний
больше 11 лет назад
debian логотип
CVE-2014-4049

Heap-based buffer overflow in the php_parserr function in ext/standard ...

CVSS2: 5.1
18%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3981

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS2: 3.3
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-3981

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3981

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

CVSS2: 3.3
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-3981

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlie ...

CVSS2: 3.3
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
10%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 4.3
10%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

CVSS2: 5
10%
Средний
больше 11 лет назад
debian логотип
CVE-2014-3710

The donote function in readelf.c in file through 5.20, as used in the ...

CVSS2: 5
10%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
36%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
36%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
36%
Средний
больше 11 лет назад

Уязвимостей на страницу