Логотип exploitDog
bind:"CVE-2014-3668" OR bind:"CVE-2014-3710" OR bind:"CVE-2014-3670" OR bind:"CVE-2014-3669"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2014-3668" OR bind:"CVE-2014-3710" OR bind:"CVE-2014-3670" OR bind:"CVE-2014-3669"

Количество 33

Количество 33

redhat логотип

CVE-2014-3670

почти 11 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2014-3670

больше 10 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2014-3670

больше 10 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PH ...

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2014-3669

больше 10 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2014-3669

почти 11 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2014-3669

больше 10 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-3669

больше 10 лет назад

Integer overflow in the object_custom function in ext/standard/var_uns ...

CVSS2: 7.5
EPSS: Средний
oracle-oval логотип

ELSA-2016-0760

около 9 лет назад

ELSA-2016-0760: file security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
github логотип

GHSA-r6jr-5phj-2qqh

около 3 лет назад

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

EPSS: Средний
github логотип

GHSA-h4mf-xgwj-q6f7

около 3 лет назад

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

EPSS: Средний
fstec логотип

BDU:2022-02651

больше 10 лет назад

Уязвимость функции object_custom интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

CVSS3: 7.3
EPSS: Средний
fstec логотип

BDU:2022-02650

больше 10 лет назад

Уязвимость расширения EXIF интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.3
EPSS: Средний
oracle-oval логотип

ELSA-2015-2155

больше 9 лет назад

ELSA-2015-2155: file security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
22%
Средний
почти 11 лет назад
nvd логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

CVSS2: 6.8
22%
Средний
больше 10 лет назад
debian логотип
CVE-2014-3670

The exif_ifd_make_value function in exif.c in the EXIF extension in PH ...

CVSS2: 6.8
22%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2014-3669

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 7.5
56%
Средний
больше 10 лет назад
redhat логотип
CVE-2014-3669

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 5.8
56%
Средний
почти 11 лет назад
nvd логотип
CVE-2014-3669

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

CVSS2: 7.5
56%
Средний
больше 10 лет назад
debian логотип
CVE-2014-3669

Integer overflow in the object_custom function in ext/standard/var_uns ...

CVSS2: 7.5
56%
Средний
больше 10 лет назад
oracle-oval логотип
ELSA-2016-0760

ELSA-2016-0760: file security, bug fix, and enhancement update (MODERATE)

около 9 лет назад
github логотип
GHSA-r6jr-5phj-2qqh

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

22%
Средний
около 3 лет назад
github логотип
GHSA-h4mf-xgwj-q6f7

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

56%
Средний
около 3 лет назад
fstec логотип
BDU:2022-02651

Уязвимость функции object_custom интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

CVSS3: 7.3
56%
Средний
больше 10 лет назад
fstec логотип
BDU:2022-02650

Уязвимость расширения EXIF интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.3
22%
Средний
больше 10 лет назад
oracle-oval логотип
ELSA-2015-2155

ELSA-2015-2155: file security and bug fix update (MODERATE)

больше 9 лет назад

Уязвимостей на страницу