Количество 15
Количество 15
CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.
CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.
CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.
CVE-2015-0231
Use-after-free vulnerability in the process_nested_data function in ex ...
GHSA-5394-7mcx-63pv
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.
BDU:2022-02653
Уязвимость функции process_nested_data интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2015:0365-1
Security update for php5
ELSA-2015-1053
ELSA-2015-1053: php55 security and bug fix update (MODERATE)
ELSA-2015-1066
ELSA-2015-1066: php54 security and bug fix update (IMPORTANT)
ELSA-2015-1135
ELSA-2015-1135: php security and bug fix update (IMPORTANT)
SUSE-SU-2015:1265-1
Security update for php53
SUSE-SU-2015:1018-1
Security update for php53
SUSE-SU-2015:0436-1
Security update for php53
SUSE-SU-2015:0370-1
Security update for php53
SUSE-SU-2016:1638-1
Security update for php53
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.  | CVSS2: 7.5  | 83% Высокий | почти 11 лет назад | |
CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.  | CVSS2: 5.1  | 83% Высокий | почти 11 лет назад | |
CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.  | CVSS2: 7.5  | 83% Высокий | почти 11 лет назад | |
CVE-2015-0231 Use-after-free vulnerability in the process_nested_data function in ex ...  | CVSS2: 7.5  | 83% Высокий | почти 11 лет назад | |
GHSA-5394-7mcx-63pv Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.  | 83% Высокий | больше 3 лет назад | ||
BDU:2022-02653 Уязвимость функции process_nested_data интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код  | CVSS3: 7.3  | 83% Высокий | почти 11 лет назад | |
SUSE-SU-2015:0365-1 Security update for php5  | больше 10 лет назад | |||
ELSA-2015-1053 ELSA-2015-1053: php55 security and bug fix update (MODERATE)  | почти 10 лет назад | |||
ELSA-2015-1066 ELSA-2015-1066: php54 security and bug fix update (IMPORTANT)  | почти 10 лет назад | |||
ELSA-2015-1135 ELSA-2015-1135: php security and bug fix update (IMPORTANT)  | больше 10 лет назад | |||
SUSE-SU-2015:1265-1 Security update for php53  | около 11 лет назад | |||
SUSE-SU-2015:1018-1 Security update for php53  | около 11 лет назад | |||
SUSE-SU-2015:0436-1 Security update for php53  | около 11 лет назад | |||
SUSE-SU-2015:0370-1 Security update for php53  | около 11 лет назад | |||
SUSE-SU-2016:1638-1 Security update for php53  | больше 9 лет назад | 
Уязвимостей на страницу