Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

ubuntu логотип

CVE-2013-6712

больше 12 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2013-6712

больше 12 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2013-6712

больше 12 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2013-6712

больше 12 лет назад

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2013-6501

около 11 лет назад

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2013-6501

около 11 лет назад

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-6501

около 11 лет назад

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2013-6501

около 11 лет назад

The default soap.wsdl_cache_dir setting in (1) php.ini-production and ...

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2013-6420

больше 12 лет назад

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2013-6420

больше 12 лет назад

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2013-6420

больше 12 лет назад

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2013-6420

больше 12 лет назад

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP befor ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2013-4636

почти 13 лет назад

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-4636

почти 13 лет назад

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4636

почти 13 лет назад

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-4636

почти 13 лет назад

The mget function in libmagic/softmagic.c in the Fileinfo component in ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-4635

почти 13 лет назад

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2013-4635

почти 13 лет назад

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2013-4635

почти 13 лет назад

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2013-4635

почти 13 лет назад

Integer overflow in the SdnToJewish function in jewish.c in the Calend ...

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

CVSS2: 5
17%
Средний
больше 12 лет назад
redhat логотип
CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

CVSS2: 2.6
17%
Средний
больше 12 лет назад
nvd логотип
CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

CVSS2: 5
17%
Средний
больше 12 лет назад
debian логотип
CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through ...

CVSS2: 5
17%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2013-6501

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 4.6
0%
Низкий
около 11 лет назад
redhat логотип
CVE-2013-6501

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 2.6
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-6501

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

CVSS2: 4.6
0%
Низкий
около 11 лет назад
debian логотип
CVE-2013-6501

The default soap.wsdl_cache_dir setting in (1) php.ini-production and ...

CVSS2: 4.6
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2013-6420

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

CVSS2: 7.5
40%
Средний
больше 12 лет назад
redhat логотип
CVE-2013-6420

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

CVSS2: 7.5
40%
Средний
больше 12 лет назад
nvd логотип
CVE-2013-6420

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

CVSS2: 7.5
40%
Средний
больше 12 лет назад
debian логотип
CVE-2013-6420

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP befor ...

CVSS2: 7.5
40%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2013-4636

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
redhat логотип
CVE-2013-4636

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-4636

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-4636

The mget function in libmagic/softmagic.c in the Fileinfo component in ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-4635

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

CVSS2: 5
13%
Средний
почти 13 лет назад
redhat логотип
CVE-2013-4635

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

CVSS2: 4.3
13%
Средний
почти 13 лет назад
nvd логотип
CVE-2013-4635

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

CVSS2: 5
13%
Средний
почти 13 лет назад
debian логотип
CVE-2013-4635

Integer overflow in the SdnToJewish function in jewish.c in the Calend ...

CVSS2: 5
13%
Средний
почти 13 лет назад

Уязвимостей на страницу