Php

Php

711 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.26%
  • Published 17.09.2016 21:59:08
  • Last modified 12.04.2025 10:46:40

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application cra...

Exploit
  • EPSS 2.03%
  • Published 17.09.2016 21:59:06
  • Last modified 12.04.2025 10:46:40

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possib...

Exploit
  • EPSS 2.32%
  • Published 17.09.2016 21:59:04
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a wddxPacket XML document...

Exploit
  • EPSS 1.73%
  • Published 17.09.2016 21:59:03
  • Last modified 12.04.2025 10:46:40

ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have un...

Exploit
  • EPSS 0.87%
  • Published 17.09.2016 21:59:02
  • Last modified 12.04.2025 10:46:40

ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that re...

  • EPSS 0.52%
  • Published 12.09.2016 01:59:12
  • Last modified 12.04.2025 10:46:40

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of service (allocation error and heap-based buffer overflow) or possibly have unspecified other impact via ...

Exploit
  • EPSS 0.5%
  • Published 12.09.2016 01:59:11
  • Last modified 12.04.2025 10:46:40

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.

Exploit
  • EPSS 6.38%
  • Published 12.09.2016 01:59:10
  • Last modified 12.04.2025 10:46:40

ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an invalid wddxPacket XML document that is ...

Exploit
  • EPSS 6.38%
  • Published 12.09.2016 01:59:09
  • Last modified 12.04.2025 10:46:40

ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via a malformed wddxPacket XML document that is...

Exploit
  • EPSS 2.56%
  • Published 12.09.2016 01:59:08
  • Last modified 12.04.2025 10:46:40

The php_wddx_pop_element function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via an inv...