Php

Php

711 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 7.14%
  • Published 11.01.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory a...

  • EPSS 1.16%
  • Published 04.01.2017 20:59:00
  • Last modified 12.04.2025 10:46:40

The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause ...

Exploit
  • EPSS 0.94%
  • Published 04.01.2017 20:59:00
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data ...

  • EPSS 2.48%
  • Published 04.01.2017 20:59:00
  • Last modified 12.04.2025 10:46:40

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated b...

  • EPSS 11.58%
  • Published 04.01.2017 20:59:00
  • Last modified 12.04.2025 10:46:40

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

  • EPSS 4.39%
  • Published 04.01.2017 20:59:00
  • Last modified 12.04.2025 10:46:40

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty bo...

Exploit
  • EPSS 0.7%
  • Published 04.01.2017 20:59:00
  • Last modified 12.04.2025 10:46:40

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exist...

  • EPSS 1.02%
  • Published 28.09.2016 20:59:02
  • Last modified 12.04.2025 10:46:40

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspe...

Exploit
  • EPSS 2.32%
  • Published 17.09.2016 21:59:10
  • Last modified 12.04.2025 10:46:40

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an inc...

Exploit
  • EPSS 2.52%
  • Published 17.09.2016 21:59:09
  • Last modified 12.04.2025 10:46:40

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impac...