Php

Php

711 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.1%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argum...

  • EPSS 1.39%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of _...

  • EPSS 8.91%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstex...

  • EPSS 0.16%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an i...

  • EPSS 0.24%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injecti...

Exploit
  • EPSS 21.55%
  • Veröffentlicht 11.01.2011 03:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation...

  • EPSS 16.66%
  • Veröffentlicht 07.12.2010 22:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via ...

  • EPSS 31.59%
  • Veröffentlicht 06.12.2010 20:13:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument.

Exploit
  • EPSS 2.98%
  • Veröffentlicht 12.11.2010 22:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 enc...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 12.11.2010 21:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protec...