Php

Php

711 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.26%
  • Published 07.09.2012 22:55:02
  • Last modified 11.04.2025 00:51:21

The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protec...

  • EPSS 7.87%
  • Published 30.08.2012 22:55:02
  • Last modified 11.04.2025 00:51:21

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a...

  • EPSS 13.83%
  • Published 06.08.2012 16:55:05
  • Last modified 11.04.2025 00:51:21

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bound...

  • EPSS 0.92%
  • Published 20.07.2012 10:40:37
  • Last modified 11.04.2025 00:51:21

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

  • EPSS 33.39%
  • Published 20.07.2012 10:40:36
  • Last modified 11.04.2025 00:51:21

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

Exploit
  • EPSS 23.12%
  • Published 07.07.2012 10:21:13
  • Last modified 11.04.2025 00:51:21

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted t...

  • EPSS 8.18%
  • Published 05.07.2012 14:55:02
  • Last modified 11.04.2025 00:51:21

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for cont...

Exploit
  • EPSS 11.85%
  • Published 24.05.2012 00:55:02
  • Last modified 11.04.2025 00:51:21

The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket) characters in name values, which makes it easier for remote attackers to cause a denial of service (malformed $_FILES indexes) or...

Exploit
  • EPSS 25.02%
  • Published 21.05.2012 15:55:02
  • Last modified 11.04.2025 00:51:21

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in Ma...

Warning Exploit
  • EPSS 94.39%
  • Published 11.05.2012 10:15:48
  • Last modified 11.04.2025 00:51:21

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...