Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 009

Количество 4 009

github логотип

GHSA-2cx4-qmrc-3ff4

больше 4 лет назад

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c9q-p5rf-5vp8

больше 4 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

EPSS: Низкий
github логотип

GHSA-2c24-m9rj-gq8m

около 4 лет назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29c3-272h-2rcq

больше 4 лет назад

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2966-gh5h-j633

больше 4 лет назад

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

EPSS: Низкий
github логотип

GHSA-28qm-wmpf-4vwh

больше 4 лет назад

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

EPSS: Низкий
github логотип

GHSA-28cw-qr46-rx46

больше 4 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

EPSS: Низкий
github логотип

GHSA-2879-hr6w-p3mx

больше 4 лет назад

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."

EPSS: Средний
github логотип

GHSA-283g-59hf-7q7h

больше 4 лет назад

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2784-39w4-9568

больше 4 лет назад

sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-276j-rjhh-4rwm

больше 4 лет назад

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

EPSS: Низкий
github логотип

GHSA-266p-jjrg-gmfx

больше 4 лет назад

** DISPUTED ** The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "There is no security issue here, because GMP safely aborts in case of an OOM condition. The only attack vector here is denial of service. However, if you allow attacker-controlled, unbounded allocations you have a DoS vector regardless of GMP's OOM behavior."

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25q8-485x-mwx9

больше 4 лет назад

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path function in ext/standard/streamsfuncs.c, as demonstrated by a filename\0.extension attack that bypasses an intended configuration in which client users may read files with only one specific extension.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25h5-rq96-q5mq

больше 4 лет назад

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-259c-37px-2x76

больше 4 лет назад

Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.

CVSS3: 9.8
EPSS: Средний
oracle-oval логотип

ELSA-2026-49914

около 1 месяца назад

ELSA-2026-49914: php8.4 security, bug fix, and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48197

около 1 месяца назад

ELSA-2026-48197: php:8.3 security, bug fix, and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48170

около 2 месяцев назад

ELSA-2026-48170: php security, bug fix, and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47750

около 1 месяца назад

ELSA-2026-47750: php:7.4 security, bug fix, and enhancement update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47749

около 1 месяца назад

ELSA-2026-47749: php:8.2 security, bug fix, and enhancement update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cx4-qmrc-3ff4

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2c9q-p5rf-5vp8

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2c24-m9rj-gq8m

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-29c3-272h-2rcq

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

CVSS3: 9.8
36%
Средний
больше 4 лет назад
github логотип
GHSA-2966-gh5h-j633

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-28qm-wmpf-4vwh

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-28cw-qr46-rx46

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2879-hr6w-p3mx

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."

14%
Средний
больше 4 лет назад
github логотип
GHSA-283g-59hf-7q7h

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a locale_get_display_name call with a long first argument.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-2784-39w4-9568

sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.

CVSS3: 9.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-276j-rjhh-4rwm

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-266p-jjrg-gmfx

** DISPUTED ** The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "There is no security issue here, because GMP safely aborts in case of an OOM condition. The only attack vector here is denial of service. However, if you allow attacker-controlled, unbounded allocations you have a DoS vector regardless of GMP's OOM behavior."

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-25q8-485x-mwx9

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path function in ext/standard/streamsfuncs.c, as demonstrated by a filename\0.extension attack that bypasses an intended configuration in which client users may read files with only one specific extension.

CVSS3: 5.3
4%
Низкий
больше 4 лет назад
github логотип
GHSA-25h5-rq96-q5mq

In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80?@good.example.com/ inputs to the parse_url function (implemented in the php_url_parse_ex function in ext/standard/url.c).

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-259c-37px-2x76

Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.

CVSS3: 9.8
15%
Средний
больше 4 лет назад
oracle-oval логотип
ELSA-2026-49914

ELSA-2026-49914: php8.4 security, bug fix, and enhancement update (LOW)

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-48197

ELSA-2026-48197: php:8.3 security, bug fix, and enhancement update (LOW)

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-48170

ELSA-2026-48170: php security, bug fix, and enhancement update (LOW)

0%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-47750

ELSA-2026-47750: php:7.4 security, bug fix, and enhancement update (LOW)

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-47749

ELSA-2026-47749: php:8.2 security, bug fix, and enhancement update (LOW)

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу