Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 009

Количество 4 009

github логотип

GHSA-866h-5php-38pf

больше 4 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

EPSS: Низкий
github логотип

GHSA-865w-9rf3-2wh5

почти 2 года назад

[PHP-FPM] Logs from childrens may be altered

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-85qm-c7q8-mxvh

больше 4 лет назад

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.

EPSS: Низкий
github логотип

GHSA-85c2-q967-79q5

4 месяца назад

Use-After-Free in SOAP using Apache map with Remote Code Execution

EPSS: Низкий
github логотип

GHSA-84wj-6mhh-jgr7

больше 4 лет назад

PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.

EPSS: Низкий
github логотип

GHSA-8472-42qg-pj78

больше 4 лет назад

PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

EPSS: Средний
github логотип

GHSA-8378-c84x-wpqv

больше 4 лет назад

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.

EPSS: Низкий
github логотип

GHSA-7xcj-pr22-cx39

больше 4 лет назад

The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.

EPSS: Низкий
github логотип

GHSA-7x98-pm42-9hc7

больше 4 лет назад

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.

EPSS: Низкий
github логотип

GHSA-7x54-3j5f-jcr9

больше 4 лет назад

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

EPSS: Средний
github логотип

GHSA-7w96-3v7r-6g9j

больше 4 лет назад

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7vjj-xv8c-grpq

больше 4 лет назад

Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

EPSS: Низкий
github логотип

GHSA-7vjg-5rq8-r4h2

больше 4 лет назад

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

EPSS: Низкий
github логотип

GHSA-7vgg-x2f9-c6c5

больше 4 лет назад

The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.

EPSS: Низкий
github логотип

GHSA-7r5x-79rr-q8gm

больше 4 лет назад

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.

EPSS: Низкий
github логотип

GHSA-7qpv-r5mr-78m4

около 2 месяцев назад

SQL injection in ext-pgsql via E'...' backslash breakout

EPSS: Низкий
github логотип

GHSA-7qg2-v9fj-4mwv

4 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
github логотип

GHSA-7pf5-hfgr-ch72

больше 4 лет назад

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-7mhv-mg92-qx3w

больше 4 лет назад

The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

EPSS: Низкий
github логотип

GHSA-7m24-mw96-fh3w

больше 4 лет назад

Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a large max parameter, as demonstrated by a value that exceeds mt_getrandmax.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-866h-5php-38pf

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-865w-9rf3-2wh5

[PHP-FPM] Logs from childrens may be altered

CVSS3: 3.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-85qm-c7q8-mxvh

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-85c2-q967-79q5

Use-After-Free in SOAP using Apache map with Remote Code Execution

1%
Низкий
4 месяца назад
github логотип
GHSA-84wj-6mhh-jgr7

PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-8472-42qg-pj78

PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

19%
Средний
больше 4 лет назад
github логотип
GHSA-8378-c84x-wpqv

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-7xcj-pr22-cx39

The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-7x98-pm42-9hc7

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-7x54-3j5f-jcr9

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

20%
Средний
больше 4 лет назад
github логотип
GHSA-7w96-3v7r-6g9j

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

CVSS3: 9.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-7vjj-xv8c-grpq

Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-7vjg-5rq8-r4h2

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-7vgg-x2f9-c6c5

The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7r5x-79rr-q8gm

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-7qpv-r5mr-78m4

SQL injection in ext-pgsql via E'...' backslash breakout

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7qg2-v9fj-4mwv

XSS within PHP-FPM status endpoint

0%
Низкий
4 месяца назад
github логотип
GHSA-7pf5-hfgr-ch72

PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-7mhv-mg92-qx3w

The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7m24-mw96-fh3w

Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a large max parameter, as demonstrated by a value that exceeds mt_getrandmax.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу