Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.51%
  • Veröffentlicht 22.05.2016 01:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...

Exploit
  • EPSS 6.48%
  • Veröffentlicht 22.05.2016 01:59:22
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...

Exploit
  • EPSS 6.48%
  • Veröffentlicht 22.05.2016 01:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 22.05.2016 01:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 22.05.2016 01:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based bu...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 22.05.2016 01:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argument to the utf8_encode function, leading to a heap-ba...

Exploit
  • EPSS 7.58%
  • Veröffentlicht 22.05.2016 01:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly ha...

Exploit
  • EPSS 5.56%
  • Veröffentlicht 22.05.2016 01:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other im...

  • EPSS 2.16%
  • Veröffentlicht 22.05.2016 01:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.

Exploit
  • EPSS 1.62%
  • Veröffentlicht 22.05.2016 01:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 mishandles driver behavior for SQL_WVARCHAR columns, which allows remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging us...