Количество 18
Количество 18
BDU:2026-01640
Уязвимость драйвера PDO для СУБД Firebird интерпретатора языка программирования PHP, позволяющая нарушителю осуществлять SQL-инъекции
ROS-20260901-80-0016
Уязвимость php 8.5
ROS-20260901-80-0015
Уязвимость php 8.4
ROS-20260901-80-0014
Уязвимость php 8.3
ROS-20260901-80-0013
Уязвимость php
ROS-20260901-73-0012
Уязвимость php 8.4
ROS-20260901-73-0011
Уязвимость php 8.3
ROS-20260901-73-0010
Уязвимость php
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
CVE-2025-14179
SQL injection in pdo_firebird via NUL bytes in quoted strings
CVE-2025-14179
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-w476-322c-wpvm
SQL injection in pdo_firebird via NUL bytes in quoted strings
SUSE-SU-2026:2037-1
Security update for php8
SUSE-SU-2026:1958-1
Security update for php8
SUSE-SU-2026:1957-1
Security update for php8
openSUSE-SU-2026:20745-1
Security update for php8
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-01640 Уязвимость драйвера PDO для СУБД Firebird интерпретатора языка программирования PHP, позволяющая нарушителю осуществлять SQL-инъекции | CVSS3: 8.1 | 0% Низкий | 7 месяцев назад | |
ROS-20260901-80-0016 Уязвимость php 8.5 | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0015 Уязвимость php 8.4 | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0014 Уязвимость php 8.3 | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0013 Уязвимость php | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0012 Уязвимость php 8.4 | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0011 Уязвимость php 8.3 | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0010 Уязвимость php | CVSS3: 8.1 | 0% Низкий | 14 дней назад | |
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. | CVSS3: 8.1 | 0% Низкий | 4 месяца назад | |
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
CVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted strings | 0% Низкий | 4 месяца назад | ||
CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-w476-322c-wpvm SQL injection in pdo_firebird via NUL bytes in quoted strings | 0% Низкий | 4 месяца назад | ||
SUSE-SU-2026:2037-1 Security update for php8 | 4 месяца назад | |||
SUSE-SU-2026:1958-1 Security update for php8 | 4 месяца назад | |||
SUSE-SU-2026:1957-1 Security update for php8 | 4 месяца назад | |||
openSUSE-SU-2026:20745-1 Security update for php8 | 4 месяца назад |
Уязвимостей на страницу