Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.36%
  • Veröffentlicht 04.01.2017 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data ...

  • EPSS 3.86%
  • Veröffentlicht 04.01.2017 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated b...

  • EPSS 6.85%
  • Veröffentlicht 04.01.2017 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.

  • EPSS 7.03%
  • Veröffentlicht 04.01.2017 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty bo...

Exploit
  • EPSS 4.3%
  • Veröffentlicht 04.01.2017 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exist...

  • EPSS 5.1%
  • Veröffentlicht 28.09.2016 20:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspe...

Exploit
  • EPSS 11.4%
  • Veröffentlicht 17.09.2016 21:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an inc...

Exploit
  • EPSS 6.84%
  • Veröffentlicht 17.09.2016 21:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impac...

Exploit
  • EPSS 6.67%
  • Veröffentlicht 17.09.2016 21:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote attackers to cause a denial of service (application cra...

Exploit
  • EPSS 6.84%
  • Veröffentlicht 17.09.2016 21:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possib...