CVE-2012-2311
- EPSS 89.96%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to exec...
- EPSS 79.57%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.
CVE-2012-2335
- EPSS 20.58%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c...
- EPSS 11.07%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service ...
- EPSS 9.13%
- Veröffentlicht 14.02.2012 15:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then ca...
- EPSS 5.69%
- Veröffentlicht 14.02.2012 15:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.
CVE-2012-0831
- EPSS 10.63%
- Veröffentlicht 10.02.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related...
CVE-2012-0830
- EPSS 30.62%
- Veröffentlicht 06.02.2012 20:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability e...
CVE-2012-0057
- EPSS 1.59%
- Veröffentlicht 02.02.2012 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.
- EPSS 4.35%
- Veröffentlicht 18.01.2012 20:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that attempts to perform Tidy::diagnose operations on invalid objec...