Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

nvd логотип

CVE-2012-3450

больше 13 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
EPSS: Средний
debian логотип

CVE-2012-3450

больше 13 лет назад

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x ...

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3365

больше 13 лет назад

The SQLite functionality in PHP before 5.3.15 allows remote attackers ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
EPSS: Средний
redhat логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 4.4
EPSS: Средний
nvd логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2012-2688

больше 13 лет назад

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2012-2386

больше 13 лет назад

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2012-2386

почти 14 лет назад

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2012-2386

больше 13 лет назад

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2012-2386

больше 13 лет назад

Integer overflow in the phar_parse_tarfile function in tar.c in the ph ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2012-2376

почти 14 лет назад

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

CVSS2: 10
EPSS: Средний
redhat логотип

CVE-2012-2376

почти 14 лет назад

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2012-2376

почти 14 лет назад

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2012-2376

почти 14 лет назад

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and ea ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2012-2336

почти 14 лет назад

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2012-2336

почти 14 лет назад

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted parameter value.

CVSS2: 2.6
12%
Средний
больше 13 лет назад
debian логотип
CVE-2012-3450

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x ...

CVSS2: 2.6
12%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-3365

The SQLite functionality in PHP before 5.3.15 allows remote attackers ...

CVSS2: 5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
33%
Средний
больше 13 лет назад
redhat логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 4.4
33%
Средний
больше 13 лет назад
nvd логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

CVSS2: 10
33%
Средний
больше 13 лет назад
debian логотип
CVE-2012-2688

Unspecified vulnerability in the _php_stream_scandir function in the s ...

CVSS2: 10
33%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-2386

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

CVSS2: 7.5
28%
Средний
больше 13 лет назад
redhat логотип
CVE-2012-2386

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

CVSS2: 6.8
28%
Средний
почти 14 лет назад
nvd логотип
CVE-2012-2386

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.

CVSS2: 7.5
28%
Средний
больше 13 лет назад
debian логотип
CVE-2012-2386

Integer overflow in the phar_parse_tarfile function in tar.c in the ph ...

CVSS2: 7.5
28%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-2376

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

CVSS2: 10
42%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-2376

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

CVSS2: 5.1
42%
Средний
почти 14 лет назад
nvd логотип
CVE-2012-2376

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in May 2012.

CVSS2: 10
42%
Средний
почти 14 лет назад
debian логотип
CVE-2012-2376

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and ea ...

CVSS2: 10
42%
Средний
почти 14 лет назад
ubuntu логотип
CVE-2012-2336

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

CVSS2: 5
53%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-2336

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service (resource consumption) by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'T' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.

CVSS2: 7.5
53%
Средний
почти 14 лет назад

Уязвимостей на страницу