CVE-2014-9426
- EPSS 0.79%
- Veröffentlicht 31.12.2014 02:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption ...
CVE-2014-9425
- EPSS 12.97%
- Veröffentlicht 31.12.2014 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact ...
CVE-2014-8142
- EPSS 88.28%
- Veröffentlicht 20.12.2014 11:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call th...
CVE-2014-8626
- EPSS 4.17%
- Veröffentlicht 23.11.2014 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone fie...
- EPSS 7.78%
- Veröffentlicht 05.11.2014 11:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and appli...
- EPSS 1.34%
- Veröffentlicht 29.10.2014 10:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (app...
CVE-2014-3669
- EPSS 66.58%
- Veröffentlicht 29.10.2014 10:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...
CVE-2014-3670
- EPSS 20.21%
- Veröffentlicht 29.10.2014 10:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory ...
CVE-2014-5459
- EPSS 0.08%
- Veröffentlicht 27.09.2014 10:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache...
CVE-2014-3597
- EPSS 5.57%
- Veröffentlicht 23.08.2014 01:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS re...