Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 8.44%
  • Veröffentlicht 25.07.2016 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified o...

Exploit
  • EPSS 2.32%
  • Veröffentlicht 25.07.2016 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecifie...

  • EPSS 4.33%
  • Veröffentlicht 25.07.2016 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

  • EPSS 83%
  • Veröffentlicht 19.07.2016 02:00:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attacker...

Exploit
  • EPSS 19.83%
  • Veröffentlicht 12.07.2016 19:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execut...

Exploit
  • EPSS 4.3%
  • Veröffentlicht 22.05.2016 01:59:29
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...

Exploit
  • EPSS 5.44%
  • Veröffentlicht 22.05.2016 01:59:28
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...

Exploit
  • EPSS 1.23%
  • Veröffentlicht 22.05.2016 01:59:27
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...

Exploit
  • EPSS 1.94%
  • Veröffentlicht 22.05.2016 01:59:26
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...

Exploit
  • EPSS 1.97%
  • Veröffentlicht 22.05.2016 01:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...