Количество 15
Количество 15

BDU:2022-02653
Уязвимость функции process_nested_data интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.

CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.

CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.
CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ex ...
GHSA-5394-7mcx-63pv
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.

SUSE-SU-2015:0365-1
Security update for php5
ELSA-2015-1053
ELSA-2015-1053: php55 security and bug fix update (MODERATE)
ELSA-2015-1066
ELSA-2015-1066: php54 security and bug fix update (IMPORTANT)
ELSA-2015-1135
ELSA-2015-1135: php security and bug fix update (IMPORTANT)

SUSE-SU-2015:1265-1
Security update for php53

SUSE-SU-2015:1018-1
Security update for php53

SUSE-SU-2015:0436-1
Security update for php53

SUSE-SU-2015:0370-1
Security update for php53

SUSE-SU-2016:1638-1
Security update for php53
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2022-02653 Уязвимость функции process_nested_data интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.3 | 87% Высокий | больше 10 лет назад |
![]() | CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142. | CVSS2: 7.5 | 87% Высокий | больше 10 лет назад |
![]() | CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142. | CVSS2: 5.1 | 87% Высокий | больше 10 лет назад |
![]() | CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142. | CVSS2: 7.5 | 87% Высокий | больше 10 лет назад |
CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ex ... | CVSS2: 7.5 | 87% Высокий | больше 10 лет назад | |
GHSA-5394-7mcx-63pv Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142. | 87% Высокий | около 3 лет назад | ||
![]() | SUSE-SU-2015:0365-1 Security update for php5 | больше 10 лет назад | ||
ELSA-2015-1053 ELSA-2015-1053: php55 security and bug fix update (MODERATE) | больше 9 лет назад | |||
ELSA-2015-1066 ELSA-2015-1066: php54 security and bug fix update (IMPORTANT) | больше 9 лет назад | |||
ELSA-2015-1135 ELSA-2015-1135: php security and bug fix update (IMPORTANT) | почти 10 лет назад | |||
![]() | SUSE-SU-2015:1265-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2015:1018-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2015:0436-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2015:0370-1 Security update for php53 | больше 10 лет назад | ||
![]() | SUSE-SU-2016:1638-1 Security update for php53 | почти 9 лет назад |
Уязвимостей на страницу