Php

Php

711 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.06%
  • Veröffentlicht 27.02.2020 21:15:18
  • Zuletzt bearbeitet 21.11.2024 05:36:35

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information ...

Exploit
  • EPSS 1.95%
  • Veröffentlicht 19.02.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 02:08:31

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

Exploit
  • EPSS 24.64%
  • Veröffentlicht 12.02.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 01:30:17

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

Exploit
  • EPSS 2.16%
  • Veröffentlicht 10.02.2020 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:35

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead t...

Exploit
  • EPSS 6.4%
  • Veröffentlicht 10.02.2020 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:35

When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the alloc...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 14.01.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 02:27:13

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a gro...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 14.01.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 02:27:13

The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call a...

Exploit
  • EPSS 35.84%
  • Veröffentlicht 23.12.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:26

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications check...

  • EPSS 7.89%
  • Veröffentlicht 23.12.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:26

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are ide...

Exploit
  • EPSS 3.17%
  • Veröffentlicht 23.12.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:26

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocate...