Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 883

Количество 3 883

suse-cvrf логотип

SUSE-SU-2018:3986-1

около 7 лет назад

Recommended update for php53

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2018:3018-1

больше 7 лет назад

Security update for php53

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3017-1

больше 7 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3016-1

больше 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:2887-1

больше 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:2640-1

больше 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1936-2

больше 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1936-1

больше 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:1886-1

больше 7 лет назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:3251-1

около 9 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2016:3211-1

около 9 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:0866-1

почти 11 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:0835-1

почти 11 лет назад

Security update for gd

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:0668-1

почти 11 лет назад

Security update for libzip

EPSS: Средний
github логотип

GHSA-xr89-hqhp-26m9

больше 3 лет назад

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-x66w-7mq7-3gxp

больше 3 лет назад

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x3xg-pxf8-v7j9

больше 3 лет назад

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-wvv6-mrff-rp8j

больше 3 лет назад

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wvm5-62cm-hw4m

больше 3 лет назад

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-wpvc-3mh7-8pwj

больше 3 лет назад

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2018:3986-1

Recommended update for php53

94%
Критический
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3018-1

Security update for php53

8%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3017-1

Security update for php5

8%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3016-1

Security update for php7

8%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:2887-1

Security update for php7

8%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:2640-1

Security update for php7

0%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1936-2

Security update for php7

6%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1936-1

Security update for php7

6%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1886-1

Security update for php7

6%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2016:3251-1

Security update for gd

11%
Средний
около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:3211-1

Security update for gd

11%
Средний
около 9 лет назад
suse-cvrf логотип
SUSE-SU-2015:0866-1

Security update for gd

17%
Средний
почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:0835-1

Security update for gd

17%
Средний
почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:0668-1

Security update for libzip

43%
Средний
почти 11 лет назад
github логотип
GHSA-xr89-hqhp-26m9

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

CVSS3: 9.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-x66w-7mq7-3gxp

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-x3xg-pxf8-v7j9

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
16%
Средний
больше 3 лет назад
github логотип
GHSA-wvv6-mrff-rp8j

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects php_parserr in ext/standard/dns.c for DNS_CAA and DNS_ANY queries.

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
github логотип
GHSA-wvm5-62cm-hw4m

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

CVSS3: 9.8
52%
Средний
больше 3 лет назад
github логотип
GHSA-wpvc-3mh7-8pwj

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу