Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 12.74%
  • Veröffentlicht 30.03.2015 10:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...

Exploit
  • EPSS 30.86%
  • Veröffentlicht 30.03.2015 10:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and applicat...

Exploit
  • EPSS 19.13%
  • Veröffentlicht 30.03.2015 10:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Exploit
  • EPSS 71.15%
  • Veröffentlicht 30.03.2015 10:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier ...

Exploit
  • EPSS 16.54%
  • Veröffentlicht 30.03.2015 10:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperl...

Exploit
  • EPSS 35.16%
  • Veröffentlicht 30.03.2015 10:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of m...

  • EPSS 6.83%
  • Veröffentlicht 30.03.2015 10:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers t...

  • EPSS 5.8%
  • Veröffentlicht 30.03.2015 10:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version...

  • EPSS 0.09%
  • Veröffentlicht 30.03.2015 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp wit...

Exploit
  • EPSS 84.87%
  • Veröffentlicht 28.01.2015 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...