Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.73%
  • Veröffentlicht 16.05.2016 10:59:23
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issu...

  • EPSS 6.2%
  • Veröffentlicht 16.05.2016 10:59:22
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not properly retrieve keys, which allows remote attackers to cause a denial of service (NULL pointer dereference, type ...

  • EPSS 7.28%
  • Veröffentlicht 16.05.2016 10:59:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding wi...

  • EPSS 6.57%
  • Veröffentlicht 16.05.2016 10:59:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility of a NULL valuePop return value before proceeding wi...

  • EPSS 36.99%
  • Veröffentlicht 16.05.2016 10:59:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafte...

  • EPSS 46.8%
  • Veröffentlicht 16.05.2016 10:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3)...

  • EPSS 6.3%
  • Veröffentlicht 16.05.2016 10:59:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (seg...

  • EPSS 6.39%
  • Veröffentlicht 16.05.2016 10:59:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a d...

Exploit
  • EPSS 16.95%
  • Veröffentlicht 16.05.2016 10:59:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer ov...

Exploit
  • EPSS 6%
  • Veröffentlicht 16.05.2016 10:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line...