Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.03.2025 06:15:13
  • Zuletzt bearbeitet 03.11.2025 21:18:52

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when t...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 29.03.2025 05:19:33
  • Zuletzt bearbeitet 03.11.2025 21:18:52

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreti...

  • EPSS 0.78%
  • Veröffentlicht 12.02.2025 22:15:29
  • Zuletzt bearbeitet 02.07.2025 21:35:56

In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may furthe...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 24.11.2024 02:15:16
  • Zuletzt bearbeitet 03.11.2025 22:16:37

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or discl...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 24.11.2024 01:15:04
  • Zuletzt bearbeitet 03.11.2025 22:16:37

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.11.2024 01:15:03
  • Zuletzt bearbeitet 03.11.2025 22:16:37

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to...

Medienbericht Exploit
  • EPSS 0.14%
  • Veröffentlicht 22.11.2024 07:15:03
  • Zuletzt bearbeitet 03.11.2025 23:17:33

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different user...

  • EPSS 0.28%
  • Veröffentlicht 22.11.2024 06:15:20
  • Zuletzt bearbeitet 03.11.2025 23:17:33

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

Medienbericht Exploit
  • EPSS 0.66%
  • Veröffentlicht 08.10.2024 04:15:11
  • Zuletzt bearbeitet 03.11.2025 23:17:33

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 char...

Exploit
  • EPSS 2.24%
  • Veröffentlicht 08.10.2024 04:15:10
  • Zuletzt bearbeitet 03.11.2025 23:17:32

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for  CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3  may still be bypasse...