Логотип exploitDog
bind:CVE-2015-8866
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-8866

Количество 11

Количество 11

ubuntu логотип

CVE-2015-8866

около 9 лет назад

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 9.6
EPSS: Низкий
redhat логотип

CVE-2015-8866

около 9 лет назад

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2015-8866

около 9 лет назад

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2015-8866

около 9 лет назад

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when ...

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-x5qj-644j-7xc7

около 3 лет назад

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 9.6
EPSS: Низкий
fstec логотип

BDU:2016-01475

около 9 лет назад

Уязвимость интерпретатора PHP, позволяющая нарушителю провести XXE- и XXL-атаки

CVSS2: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1310-1

около 9 лет назад

Security update for php53

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:1373-1

около 9 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1277-1

около 9 лет назад

Security update for php5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1581-1

около 9 лет назад

Security update for php53

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:1638-1

почти 9 лет назад

Security update for php53

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-8866

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 9.6
7%
Низкий
около 9 лет назад
redhat логотип
CVE-2015-8866

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 3.7
7%
Низкий
около 9 лет назад
nvd логотип
CVE-2015-8866

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 9.6
7%
Низкий
около 9 лет назад
debian логотип
CVE-2015-8866

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when ...

CVSS3: 9.6
7%
Низкий
около 9 лет назад
github логотип
GHSA-x5qj-644j-7xc7

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

CVSS3: 9.6
7%
Низкий
около 3 лет назад
fstec логотип
BDU:2016-01475

Уязвимость интерпретатора PHP, позволяющая нарушителю провести XXE- и XXL-атаки

CVSS2: 6.8
7%
Низкий
около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1310-1

Security update for php53

около 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1373-1

Security update for php5

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1277-1

Security update for php5

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1581-1

Security update for php53

около 9 лет назад
suse-cvrf логотип
SUSE-SU-2016:1638-1

Security update for php53

почти 9 лет назад

Уязвимостей на страницу