Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.54%
  • Veröffentlicht 22.05.2016 01:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary ...

Exploit
  • EPSS 7.29%
  • Veröffentlicht 20.05.2016 11:00:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute...

  • EPSS 5.93%
  • Veröffentlicht 20.05.2016 11:00:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of \0 characters by the phar_analyze_path function in ext/phar...

Exploit
  • EPSS 19.46%
  • Veröffentlicht 20.05.2016 11:00:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call.

Exploit
  • EPSS 5.72%
  • Veröffentlicht 20.05.2016 11:00:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode f...

Exploit
  • EPSS 5.42%
  • Veröffentlicht 20.05.2016 10:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The file_check_mem function in funcs.c in file before 5.23, as used in the Fileinfo component in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5, mishandles continuation-level jumps, which allows context-dependent attackers to cause a de...

  • EPSS 3.15%
  • Veröffentlicht 16.05.2016 10:59:27
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (...

Exploit
  • EPSS 11%
  • Veröffentlicht 16.05.2016 10:59:26
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TAR archive...

Exploit
  • EPSS 8.28%
  • Veröffentlicht 16.05.2016 10:59:25
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Stack consumption vulnerability in GD in PHP before 5.6.12 allows remote attackers to cause a denial of service via a crafted imagefilltoborder call.

Exploit
  • EPSS 3.88%
  • Veröffentlicht 16.05.2016 10:59:24
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Stack consumption vulnerability in Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to cause a denial of service (segmentation fault) via recursive method calls.