CVE-2014-4721
- EPSS 9.94%
- Veröffentlicht 06.07.2014 23:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent ...
- EPSS 10.25%
- Veröffentlicht 03.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. N...
CVE-2014-4049
- EPSS 22.41%
- Veröffentlicht 18.06.2014 19:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns...
CVE-2014-3981
- EPSS 0.17%
- Veröffentlicht 08.06.2014 18:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.
- EPSS 23.09%
- Veröffentlicht 01.06.2014 04:29:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.
- EPSS 30.64%
- Veröffentlicht 01.06.2014 04:29:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero len...
CVE-2014-0185
- EPSS 0.11%
- Veröffentlicht 06.05.2014 10:44:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.
- EPSS 1.53%
- Veröffentlicht 24.03.2014 16:31:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a cra...
CVE-2014-2497
- EPSS 12.14%
- Veröffentlicht 21.03.2014 14:55:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
CVE-2014-2270
- EPSS 43.46%
- Veröffentlicht 14.03.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.