Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 21

Количество 21

fstec логотип

BDU:2023-06656

почти 3 года назад

Уязвимость интерпретатора языка программирования PHP, связанная с неверным ограничением XML-ссылок на внешний объект, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным

CVSS3: 8.6
EPSS: Низкий
redos логотип

ROS-20240816-14

почти 2 года назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20240816-08

почти 2 года назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-3823

почти 3 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-3823

почти 3 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-3823

почти 3 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2023-3823

почти 3 года назад

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-3823

почти 3 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3qrf-m4j2-pcrr

почти 3 года назад

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3541-1

почти 3 года назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3528-1

почти 3 года назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3498-1

почти 3 года назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3445-1

почти 3 года назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2024:0387

больше 2 лет назад

Moderate: php:8.1 security update

EPSS: Низкий
rocky логотип

RLSA-2023:5927

больше 2 лет назад

Important: php:8.0 security update

EPSS: Низкий
rocky логотип

RLSA-2023:5926

больше 2 лет назад

Important: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0387

больше 2 лет назад

ELSA-2024-0387: php:8.1 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5927

больше 2 лет назад

ELSA-2023-5927: php:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5926

больше 2 лет назад

ELSA-2023-5926: php security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2024:10952

больше 1 года назад

Moderate: php:7.4 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-06656

Уязвимость интерпретатора языка программирования PHP, связанная с неверным ограничением XML-ссылок на внешний объект, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным

CVSS3: 8.6
1%
Низкий
почти 3 года назад
redos логотип
ROS-20240816-14

Множественные уязвимости php

CVSS3: 9.8
почти 2 года назад
redos логотип
ROS-20240816-08

Множественные уязвимости php

CVSS3: 9.8
почти 2 года назад
ubuntu логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
1%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-3823

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ...

CVSS3: 8.6
1%
Низкий
почти 3 года назад
github логотип
GHSA-3qrf-m4j2-pcrr

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
1%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:3541-1

Security update for php7

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:3528-1

Security update for php7

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:3498-1

Security update for php7

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:3445-1

Security update for php7

почти 3 года назад
rocky логотип
RLSA-2024:0387

Moderate: php:8.1 security update

больше 2 лет назад
rocky логотип
RLSA-2023:5927

Important: php:8.0 security update

больше 2 лет назад
rocky логотип
RLSA-2023:5926

Important: php security update

больше 2 лет назад
oracle-oval логотип
ELSA-2024-0387

ELSA-2024-0387: php:8.1 security update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-5927

ELSA-2023-5927: php:8.0 security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-5926

ELSA-2023-5926: php security update (IMPORTANT)

больше 2 лет назад
rocky логотип
RLSA-2024:10952

Moderate: php:7.4 security update

больше 1 года назад

Уязвимостей на страницу