Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 010

Количество 4 010

github логотип

GHSA-3fj4-q72x-x2g9

больше 4 лет назад

ADOdb Library SQL Injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-39rv-383r-32wp

больше 4 лет назад

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

EPSS: Низкий
github логотип

GHSA-39ch-q5j8-9rjh

больше 4 лет назад

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-35p7-xqgq-2gx7

больше 4 лет назад

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-33vf-9722-2226

больше 4 лет назад

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

EPSS: Низкий
github логотип

GHSA-33jw-h57w-fr79

больше 4 лет назад

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.

EPSS: Низкий
github логотип

GHSA-2r4w-c5qm-vpx8

больше 4 лет назад

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

EPSS: Низкий
github логотип

GHSA-2396-h4jp-vpjg

больше 4 лет назад

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.

CVSS3: 7.5
EPSS: Средний
oracle-oval логотип

ELSA-2020-5443

почти 6 лет назад

ELSA-2020-5443: gd security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-1634

около 11 лет назад

ELSA-2015-1634: sqlite security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1036

около 14 лет назад

ELSA-2012-1036: postgresql security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2010-0003

больше 16 лет назад

ELSA-2010-0003: gd security update (MODERATE)

EPSS: Средний
ubuntu логотип

CVE-2025-1861

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-1861

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-1861

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-1861

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-1736

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2025-1736

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2025-1736

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-1736

больше 1 года назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fj4-q72x-x2g9

ADOdb Library SQL Injection

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-39rv-383r-32wp

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-39ch-q5j8-9rjh

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS3: 9.8
20%
Средний
больше 4 лет назад
github логотип
GHSA-35p7-xqgq-2gx7

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 9.8
42%
Средний
больше 4 лет назад
github логотип
GHSA-33vf-9722-2226

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-33jw-h57w-fr79

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-2r4w-c5qm-vpx8

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2396-h4jp-vpjg

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.

CVSS3: 7.5
10%
Средний
больше 4 лет назад
oracle-oval логотип
ELSA-2020-5443

ELSA-2020-5443: gd security update (MODERATE)

7%
Низкий
почти 6 лет назад
oracle-oval логотип
ELSA-2015-1634

ELSA-2015-1634: sqlite security update (MODERATE)

6%
Низкий
около 11 лет назад
oracle-oval логотип
ELSA-2012-1036

ELSA-2012-1036: postgresql security update (MODERATE)

6%
Низкий
около 14 лет назад
oracle-oval логотип
ELSA-2010-0003

ELSA-2010-0003: gd security update (MODERATE)

10%
Средний
больше 16 лет назад
ubuntu логотип
CVE-2025-1861

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-1861

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-1861

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
debian логотип
CVE-2025-1861

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...

CVSS3: 9.8
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-1736

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-1736

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 3.7
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-1736

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2025-1736

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...

CVSS3: 7.3
1%
Низкий
больше 1 года назад

Уязвимостей на страницу