Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

ubuntu логотип

CVE-2014-3515

больше 11 лет назад

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2014-3515

больше 11 лет назад

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2014-3515

больше 11 лет назад

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-3515

больше 11 лет назад

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorre ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2014-2497

около 12 лет назад

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2014-2497

около 12 лет назад

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2014-2497

около 12 лет назад

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2014-2497

около 12 лет назад

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2014-2020

около 12 лет назад

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-2020

около 12 лет назад

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-2020

около 12 лет назад

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-2020

около 12 лет назад

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-0238

почти 12 лет назад

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2014-0238

почти 12 лет назад

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2014-0238

почти 12 лет назад

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-0238

почти 12 лет назад

The cdf_read_property_info function in cdf.c in the Fileinfo component ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-0237

почти 12 лет назад

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2014-0237

почти 12 лет назад

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2014-0237

почти 12 лет назад

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2014-0237

почти 12 лет назад

The cdf_unpack_summary_info function in cdf.c in the Fileinfo componen ...

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-3515

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 7.5
61%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-3515

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 5.1
61%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-3515

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable destructor, related to "type confusion" issues in (1) ArrayObject and (2) SPLObjectStorage.

CVSS2: 7.5
61%
Средний
больше 11 лет назад
debian логотип
CVE-2014-3515

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorre ...

CVSS2: 7.5
61%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-2497

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

CVSS2: 4.3
12%
Средний
около 12 лет назад
redhat логотип
CVE-2014-2497

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

CVSS2: 2.6
12%
Средний
около 12 лет назад
nvd логотип
CVE-2014-2497

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

CVSS2: 4.3
12%
Средний
около 12 лет назад
debian логотип
CVE-2014-2497

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP ...

CVSS2: 4.3
12%
Средний
около 12 лет назад
ubuntu логотип
CVE-2014-2020

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

CVSS2: 5
0%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-2020

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

CVSS2: 6.8
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2014-2020

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

CVSS2: 5
0%
Низкий
около 12 лет назад
debian логотип
CVE-2014-2020

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which ...

CVSS2: 5
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-0238

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

CVSS2: 5
26%
Средний
почти 12 лет назад
redhat логотип
CVE-2014-0238

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

CVSS2: 4.3
26%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-0238

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

CVSS2: 5
26%
Средний
почти 12 лет назад
debian логотип
CVE-2014-0238

The cdf_read_property_info function in cdf.c in the Fileinfo component ...

CVSS2: 5
26%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-0237

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

CVSS2: 5
38%
Средний
почти 12 лет назад
redhat логотип
CVE-2014-0237

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

CVSS2: 4.3
38%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-0237

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

CVSS2: 5
38%
Средний
почти 12 лет назад
debian логотип
CVE-2014-0237

The cdf_unpack_summary_info function in cdf.c in the Fileinfo componen ...

CVSS2: 5
38%
Средний
почти 12 лет назад

Уязвимостей на страницу