Php

Php

711 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.43%
  • Published 19.02.2018 19:29:00
  • Last modified 21.11.2024 02:40:09

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system...

Exploit
  • EPSS 0.56%
  • Published 09.02.2018 06:29:00
  • Last modified 21.11.2024 02:44:34

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "...

  • EPSS 9.3%
  • Published 16.01.2018 09:29:00
  • Last modified 21.11.2024 04:09:13

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated...

  • EPSS 89.19%
  • Published 16.01.2018 09:29:00
  • Last modified 21.11.2024 04:09:13

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.

Exploit
  • EPSS 8.37%
  • Published 07.11.2017 21:29:00
  • Last modified 20.04.2025 01:37:25

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the in...

  • EPSS 1.77%
  • Published 18.08.2017 03:29:00
  • Last modified 20.04.2025 01:37:25

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array s...

  • EPSS 16.71%
  • Published 18.08.2017 03:29:00
  • Last modified 20.04.2025 01:37:25

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecifie...

  • EPSS 0.49%
  • Published 18.08.2017 03:29:00
  • Last modified 20.04.2025 01:37:25

ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have a...

  • EPSS 19.47%
  • Published 02.08.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitia...

  • EPSS 0.15%
  • Published 25.07.2017 23:29:00
  • Last modified 20.04.2025 01:37:25

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant...