- EPSS 42.03%
- Veröffentlicht 09.06.2015 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote attackers to cause a de...
CVE-2015-3330
- EPSS 38.96%
- Veröffentlicht 09.06.2015 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or p...
CVE-2015-3329
- EPSS 28.15%
- Veröffentlicht 09.06.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...
CVE-2015-3307
- EPSS 18.41%
- Veröffentlicht 09.06.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a craf...
CVE-2015-2783
- EPSS 9.68%
- Veröffentlicht 09.06.2015 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length v...
CVE-2015-1863
- EPSS 5.38%
- Veröffentlicht 28.04.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2...
- EPSS 1.52%
- Veröffentlicht 08.04.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
- EPSS 17.76%
- Veröffentlicht 08.04.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evalu...
CVE-2015-2787
- EPSS 36.43%
- Veröffentlicht 30.03.2015 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call th...
- EPSS 7.24%
- Veröffentlicht 30.03.2015 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extens...