Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.27%
  • Veröffentlicht 25.07.2016 14:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9, allows remote attackers to cause a denial of service (heap-based buffe...

Exploit
  • EPSS 5.42%
  • Veröffentlicht 25.07.2016 14:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to cause a denial of service (use-after-free and applicatio...

Exploit
  • EPSS 5.96%
  • Veröffentlicht 25.07.2016 14:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly restrict calls to the ICU uloc_acceptLanguageFromHTTP function, which allows remote attackers t...

Exploit
  • EPSS 3.91%
  • Veröffentlicht 25.07.2016 14:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted JPEG image.

Exploit
  • EPSS 5.6%
  • Veröffentlicht 25.07.2016 14:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive in...

  • EPSS 5.48%
  • Veröffentlicht 25.07.2016 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certain hash data structure, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified o...

Exploit
  • EPSS 3.79%
  • Veröffentlicht 25.07.2016 14:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecifie...

  • EPSS 5.06%
  • Veröffentlicht 25.07.2016 14:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

  • EPSS 50.43%
  • Veröffentlicht 19.07.2016 02:00:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attacker...

Exploit
  • EPSS 12.29%
  • Veröffentlicht 12.07.2016 19:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execut...