Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 37.24%
  • Veröffentlicht 16.05.2016 10:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3)...

  • EPSS 10.38%
  • Veröffentlicht 16.05.2016 10:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (seg...

  • EPSS 9.89%
  • Veröffentlicht 16.05.2016 10:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a d...

Exploit
  • EPSS 8.66%
  • Veröffentlicht 16.05.2016 10:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer ov...

Exploit
  • EPSS 5.95%
  • Veröffentlicht 16.05.2016 10:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line...

Exploit
  • EPSS 9.11%
  • Veröffentlicht 16.05.2016 10:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of ...

Exploit
  • EPSS 9.11%
  • Veröffentlicht 16.05.2016 10:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a den...

Exploit
  • EPSS 8.13%
  • Veröffentlicht 16.05.2016 10:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

Exploit
  • EPSS 12.86%
  • Veröffentlicht 16.05.2016 10:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a...

  • EPSS 21.38%
  • Veröffentlicht 16.05.2016 10:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c,...