CVE-2017-9228
- EPSS 6.26%
- Veröffentlicht 24.05.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular expression compilation due to an uninitialized variab...
CVE-2017-9229
- EPSS 5.13%
- Veröffentlicht 24.05.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during regular expression compilation. Invalid handling of reg->dmax in forward_...
CVE-2017-9119
- EPSS 3.56%
- Veröffentlicht 21.05.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data struc...
- EPSS 0.82%
- Veröffentlicht 18.05.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
CVE-2017-8923
- EPSS 7.19%
- Veröffentlicht 12.05.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have un...
CVE-2016-5399
- EPSS 9.84%
- Veröffentlicht 21.04.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted bz2 archive.
CVE-2017-7963
- EPSS 2%
- Veröffentlicht 19.04.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "Ther...
CVE-2017-6441
- EPSS 1.83%
- Veröffentlicht 03.04.2017 05:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classif...
CVE-2017-7272
- EPSS 3.51%
- Veröffentlicht 27.03.2017 17:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that ...
CVE-2015-8994
- EPSS 2.94%
- Veröffentlicht 02.03.2017 06:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28 or 7.x after 7.0.13, the issue is resolved in a non-default configuration with the opcache.validate_...