Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 27.12.2025 19:33:23
  • Zuletzt bearbeitet 08.01.2026 22:03:28

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-ch...

  • EPSS 0.06%
  • Veröffentlicht 27.12.2025 19:27:41
  • Zuletzt bearbeitet 24.01.2026 11:15:49

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE,...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 27.12.2025 19:21:20
  • Zuletzt bearbeitet 09.01.2026 20:23:40

In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a pre...

  • EPSS 0.07%
  • Veröffentlicht 13.07.2025 22:27:48
  • Zuletzt bearbeitet 04.11.2025 22:16:06

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the stri...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 13.07.2025 22:18:36
  • Zuletzt bearbeitet 04.11.2025 22:16:06

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like pars...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 13.07.2025 22:15:23
  • Zuletzt bearbeitet 04.11.2025 22:16:43

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and a...

Exploit
  • EPSS 1.47%
  • Veröffentlicht 04.04.2025 17:51:07
  • Zuletzt bearbeitet 30.04.2025 19:25:17

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for exam...

  • EPSS 0.38%
  • Veröffentlicht 30.03.2025 06:15:14
  • Zuletzt bearbeitet 03.11.2025 21:18:52

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may con...

  • EPSS 0.65%
  • Veröffentlicht 30.03.2025 06:15:14
  • Zuletzt bearbeitet 03.11.2025 21:18:52

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent o...

  • EPSS 0.94%
  • Veröffentlicht 30.03.2025 06:15:14
  • Zuletzt bearbeitet 03.11.2025 21:18:53

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of...