Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 51.09%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishan...

  • EPSS 2.27%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a Make...

Exploit
  • EPSS 83.07%
  • Veröffentlicht 01.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:25

In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This ...

Exploit
  • EPSS 2.96%
  • Veröffentlicht 19.02.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 02:40:09

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 09.02.2018 06:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:34

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "...

  • EPSS 10.27%
  • Veröffentlicht 16.01.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:13

gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated...

  • EPSS 87.61%
  • Veröffentlicht 16.01.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:13

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.

Exploit
  • EPSS 8.37%
  • Veröffentlicht 07.11.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the in...

  • EPSS 1.77%
  • Veröffentlicht 18.08.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array s...

  • EPSS 16.71%
  • Veröffentlicht 18.08.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecifie...