Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 9.4%
  • Veröffentlicht 09.03.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:02

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

Exploit
  • EPSS 10.06%
  • Veröffentlicht 22.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:49

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is rel...

Exploit
  • EPSS 10.06%
  • Veröffentlicht 22.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:49

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory ...

Exploit
  • EPSS 4.19%
  • Veröffentlicht 22.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:49

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buff...

Exploit
  • EPSS 9.32%
  • Veröffentlicht 22.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:49

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte ...

Exploit
  • EPSS 7.12%
  • Veröffentlicht 22.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:50

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlr...

Exploit
  • EPSS 3.07%
  • Veröffentlicht 22.02.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:50:50

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write pas...

Exploit
  • EPSS 5.66%
  • Veröffentlicht 21.02.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:09

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. ...

Exploit
  • EPSS 64.27%
  • Veröffentlicht 27.01.2019 02:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:20

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This c...

  • EPSS 6.28%
  • Veröffentlicht 07.12.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:50

ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.