Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.84%
  • Veröffentlicht 12.09.2016 01:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impa...

Exploit
  • EPSS 8.82%
  • Veröffentlicht 12.09.2016 01:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which allows remote attackers to cause a denial of service (select_colors allocation error and out-of-boun...

Exploit
  • EPSS 5.78%
  • Veröffentlicht 12.09.2016 01:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session name, as dem...

Exploit
  • EPSS 16.61%
  • Veröffentlicht 12.09.2016 01:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads...

  • EPSS 6.26%
  • Veröffentlicht 12.08.2016 15:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vecto...

Exploit
  • EPSS 9.26%
  • Veröffentlicht 07.08.2016 10:59:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial ...

Exploit
  • EPSS 9.67%
  • Veröffentlicht 07.08.2016 10:59:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execu...

Exploit
  • EPSS 15.48%
  • Veröffentlicht 07.08.2016 10:59:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-a...

Exploit
  • EPSS 7.34%
  • Veröffentlicht 07.08.2016 10:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large inte...

  • EPSS 8.36%
  • Veröffentlicht 07.08.2016 10:59:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have uns...