Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 883

Количество 3 883

nvd логотип

CVE-2012-0057

около 14 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-0057

около 14 лет назад

PHP before 5.3.9 has improper libxslt security settings, which allows ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4885

около 14 лет назад

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
EPSS: Высокий
redhat логотип

CVE-2011-4885

около 14 лет назад

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2011-4885

около 14 лет назад

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2011-4885

около 14 лет назад

PHP before 5.3.9 computes hash values for form parameters without rest ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2011-4718

больше 12 лет назад

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2011-4718

около 14 лет назад

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-4718

больше 12 лет назад

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4718

больше 12 лет назад

Session fixation vulnerability in the Sessions subsystem in PHP before ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4566

около 14 лет назад

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 6.4
EPSS: Средний
redhat логотип

CVE-2011-4566

больше 14 лет назад

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2011-4566

около 14 лет назад

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 6.4
EPSS: Средний
debian логотип

CVE-2011-4566

около 14 лет назад

Integer overflow in the exif_process_IFD_TAG function in exif.c in the ...

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2011-4153

около 14 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2011-4153

около 14 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4153

около 14 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4153

около 14 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup f ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3379

больше 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2011-3379

больше 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-0057

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

CVSS2: 6.4
2%
Низкий
около 14 лет назад
debian логотип
CVE-2012-0057

PHP before 5.3.9 has improper libxslt security settings, which allows ...

CVSS2: 6.4
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-4885

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
89%
Высокий
около 14 лет назад
redhat логотип
CVE-2011-4885

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
89%
Высокий
около 14 лет назад
nvd логотип
CVE-2011-4885

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS2: 5
89%
Высокий
около 14 лет назад
debian логотип
CVE-2011-4885

PHP before 5.3.9 computes hash values for form parameters without rest ...

CVSS2: 5
89%
Высокий
около 14 лет назад
ubuntu логотип
CVE-2011-4718

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2011-4718

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

CVSS2: 5.8
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4718

Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID.

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2011-4718

Session fixation vulnerability in the Sessions subsystem in PHP before ...

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-4566

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 6.4
44%
Средний
около 14 лет назад
redhat логотип
CVE-2011-4566

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 5.8
44%
Средний
больше 14 лет назад
nvd логотип
CVE-2011-4566

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS2: 6.4
44%
Средний
около 14 лет назад
debian логотип
CVE-2011-4566

Integer overflow in the exif_process_IFD_TAG function in exif.c in the ...

CVSS2: 6.4
44%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 5
6%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 4.3
6%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 5
6%
Низкий
около 14 лет назад
debian логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup f ...

CVSS2: 5
6%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
redhat логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 5.1
1%
Низкий
больше 14 лет назад

Уязвимостей на страницу