Php

Php

711 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.16%
  • Veröffentlicht 12.09.2016 01:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via an invalid ISO 8601 time value, a...

Exploit
  • EPSS 1.47%
  • Veröffentlicht 12.09.2016 01:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memor...

Exploit
  • EPSS 1.5%
  • Veröffentlicht 12.09.2016 01:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impa...

Exploit
  • EPSS 4.63%
  • Veröffentlicht 12.09.2016 01:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which allows remote attackers to cause a denial of service (select_colors allocation error and out-of-boun...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 12.09.2016 01:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as dem...

Exploit
  • EPSS 74.44%
  • Veröffentlicht 12.09.2016 01:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads...

  • EPSS 10.16%
  • Veröffentlicht 12.08.2016 15:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vecto...

Exploit
  • EPSS 21.13%
  • Veröffentlicht 07.08.2016 10:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial ...

Exploit
  • EPSS 15.31%
  • Veröffentlicht 07.08.2016 10:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execu...

Exploit
  • EPSS 13.65%
  • Veröffentlicht 07.08.2016 10:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-a...