Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 34.9%
  • Veröffentlicht 31.03.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by trig...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 19.01.2016 05:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a long string to the (1) php_escape_shell_cmd or (2) php_escape_shell_arg func...

Exploit
  • EPSS 8.69%
  • Veröffentlicht 19.01.2016 05:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and app...

Exploit
  • EPSS 27.14%
  • Veröffentlicht 19.01.2016 05:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to ...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 19.01.2016 05:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by...

  • EPSS 3.43%
  • Veröffentlicht 19.01.2016 05:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "...

  • EPSS 0.4%
  • Veröffentlicht 19.01.2016 05:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled during an extr...

  • EPSS 1.54%
  • Veröffentlicht 19.01.2016 05:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers m...

  • EPSS 1.16%
  • Veröffentlicht 19.01.2016 05:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedLis...

Exploit
  • EPSS 2.62%
  • Veröffentlicht 19.01.2016 05:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplace function.