Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 7.56%
  • Veröffentlicht 02.08.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:35:22

PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string.

  • EPSS 6.8%
  • Veröffentlicht 26.06.2018 03:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:02

exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PH...

  • EPSS 0.83%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one u...

  • EPSS 10.43%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.

  • EPSS 3.63%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE:...

  • EPSS 8.68%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishan...

  • EPSS 7.16%
  • Veröffentlicht 29.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:32

An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a Make...

Exploit
  • EPSS 87.35%
  • Veröffentlicht 01.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:25

In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This ...

Exploit
  • EPSS 4.18%
  • Veröffentlicht 19.02.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 02:40:09

An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system...

Exploit
  • EPSS 2.25%
  • Veröffentlicht 09.02.2018 06:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:34

In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "...