Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.18%
  • Veröffentlicht 22.05.2016 01:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argument to the utf8_encode function, leading to a heap-ba...

Exploit
  • EPSS 4.21%
  • Veröffentlicht 22.05.2016 01:59:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly ha...

Exploit
  • EPSS 5.35%
  • Veröffentlicht 22.05.2016 01:59:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other im...

  • EPSS 2.95%
  • Veröffentlicht 22.05.2016 01:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.

Exploit
  • EPSS 3.42%
  • Veröffentlicht 22.05.2016 01:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 mishandles driver behavior for SQL_WVARCHAR columns, which allows remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging us...

  • EPSS 1.25%
  • Veröffentlicht 22.05.2016 01:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that perfor...

Exploit
  • EPSS 3.65%
  • Veröffentlicht 22.05.2016 01:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memo...

Exploit
  • EPSS 7.71%
  • Veröffentlicht 22.05.2016 01:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trig...

  • EPSS 4.35%
  • Veröffentlicht 22.05.2016 01:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat...

Exploit
  • EPSS 4.03%
  • Veröffentlicht 22.05.2016 01:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML...