Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 17.14%
  • Veröffentlicht 21.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.

  • EPSS 1.67%
  • Veröffentlicht 19.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "Ther...

  • EPSS 0.42%
  • Veröffentlicht 03.04.2017 05:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classif...

  • EPSS 1.11%
  • Veröffentlicht 27.03.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that ...

Exploit
  • EPSS 2%
  • Veröffentlicht 02.03.2017 06:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28 or 7.x after 7.0.13, the issue is resolved in a non-default configuration with the opcache.validate_...

  • EPSS 4.99%
  • Veröffentlicht 24.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divid...

  • EPSS 10.26%
  • Veröffentlicht 24.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PH...

  • EPSS 4.7%
  • Veröffentlicht 24.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archiv...

  • EPSS 14.63%
  • Veröffentlicht 24.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data...

  • EPSS 4%
  • Veröffentlicht 24.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7.0.x before 7.0.15 and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacke...