Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 843

Количество 3 843

nvd логотип

CVE-2016-8670

больше 8 лет назад

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted imagecreatefromstring call.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-8670

больше 8 лет назад

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c i ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7568

почти 9 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-7568

почти 9 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2016-7568

почти 9 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-7568

почти 9 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7480

больше 8 лет назад

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-7480

почти 9 лет назад

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-7480

больше 8 лет назад

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-7480

больше 8 лет назад

The SplObjectStorage unserialize implementation in ext/spl/spl_observe ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7405

почти 9 лет назад

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-7405

почти 9 лет назад

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-7405

почти 9 лет назад

The qstr method in the PDO driver in the ADOdb Library for PHP before ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-6207

около 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-6207

около 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2016-6207

около 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-6207

около 9 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpola ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-6174

около 9 лет назад

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.

CVSS3: 8.1
EPSS: Средний
ubuntu логотип

CVE-2016-6128

около 9 лет назад

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-6128

около 9 лет назад

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-8670

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted imagecreatefromstring call.

CVSS3: 9.8
2%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-8670

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c i ...

CVSS3: 9.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2016-7568

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
1%
Низкий
почти 9 лет назад
redhat логотип
CVE-2016-7568

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 7.1
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-7568

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2016-7568

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD ...

CVSS3: 9.8
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-7480

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 9.8
5%
Низкий
больше 8 лет назад
redhat логотип
CVE-2016-7480

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 8.1
5%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-7480

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 9.8
5%
Низкий
больше 8 лет назад
debian логотип
CVE-2016-7480

The SplObjectStorage unserialize implementation in ext/spl/spl_observe ...

CVSS3: 9.8
5%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2016-7405

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

CVSS3: 9.8
3%
Низкий
почти 9 лет назад
nvd логотип
CVE-2016-7405

The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

CVSS3: 9.8
3%
Низкий
почти 9 лет назад
debian логотип
CVE-2016-7405

The qstr method in the PDO driver in the ADOdb Library for PHP before ...

CVSS3: 9.8
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
5%
Низкий
около 9 лет назад
redhat логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.2
5%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.5
5%
Низкий
около 9 лет назад
debian логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpola ...

CVSS3: 6.5
5%
Низкий
около 9 лет назад
nvd логотип
CVE-2016-6174

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.

CVSS3: 8.1
23%
Средний
около 9 лет назад
ubuntu логотип
CVE-2016-6128

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 7.5
6%
Низкий
около 9 лет назад
redhat логотип
CVE-2016-6128

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

CVSS3: 3.7
6%
Низкий
около 9 лет назад

Уязвимостей на страницу