Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 768

Количество 3 768

suse-cvrf логотип

SUSE-SU-2018:2887-1

почти 7 лет назад

Security update for php7

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2018:2640-1

почти 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1936-2

почти 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1936-1

почти 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1886-1

почти 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3251-1

больше 8 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2016:3211-1

больше 8 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:0866-1

больше 10 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:0835-1

больше 10 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:0668-1

больше 10 лет назад

Security update for libzip

EPSS: Средний
github логотип

GHSA-xr89-hqhp-26m9

около 3 лет назад

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-x66w-7mq7-3gxp

около 3 лет назад

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x3xg-pxf8-v7j9

около 3 лет назад

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-wvv6-mrff-rp8j

около 3 лет назад

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wvm5-62cm-hw4m

около 3 лет назад

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-wpvc-3mh7-8pwj

около 3 лет назад

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wpfq-fvm4-44jm

около 3 лет назад

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-wfcw-88hm-m2xm

около 3 лет назад

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

EPSS: Средний
github логотип

GHSA-w8f6-vcfx-23xp

около 3 лет назад

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-w7xp-2c87-fchc

около 3 лет назад

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2018:2887-1

Security update for php7

26%
Средний
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:2640-1

Security update for php7

0%
Низкий
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1936-2

Security update for php7

4%
Низкий
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1936-1

Security update for php7

4%
Низкий
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1886-1

Security update for php7

4%
Низкий
почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2016:3251-1

Security update for gd

11%
Средний
больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2016:3211-1

Security update for gd

11%
Средний
больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2015:0866-1

Security update for gd

15%
Средний
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0835-1

Security update for gd

15%
Средний
больше 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:0668-1

Security update for libzip

43%
Средний
больше 10 лет назад
github логотип
GHSA-xr89-hqhp-26m9

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-x66w-7mq7-3gxp

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
7%
Низкий
около 3 лет назад
github логотип
GHSA-x3xg-pxf8-v7j9

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
11%
Средний
около 3 лет назад
github логотип
GHSA-wvv6-mrff-rp8j

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.

CVSS3: 7.5
7%
Низкий
около 3 лет назад
github логотип
GHSA-wvm5-62cm-hw4m

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

CVSS3: 9.8
51%
Средний
около 3 лет назад
github логотип
GHSA-wpvc-3mh7-8pwj

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-wpfq-fvm4-44jm

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.

CVSS3: 8.1
20%
Средний
около 3 лет назад
github логотип
GHSA-wfcw-88hm-m2xm

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

43%
Средний
около 3 лет назад
github логотип
GHSA-w8f6-vcfx-23xp

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

CVSS3: 9.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-w7xp-2c87-fchc

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

3%
Низкий
около 3 лет назад

Уязвимостей на страницу