CVE-2015-0232
- EPSS 68.27%
- Veröffentlicht 27.01.2015 20:04:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) v...
CVE-2015-0231
- EPSS 87.28%
- Veröffentlicht 27.01.2015 20:03:41
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call th...
CVE-2014-9427
- EPSS 4.87%
- Veröffentlicht 03.01.2015 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins wit...
CVE-2014-9426
- EPSS 0.79%
- Veröffentlicht 31.12.2014 02:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption ...
CVE-2014-9425
- EPSS 15.81%
- Veröffentlicht 31.12.2014 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact ...
CVE-2014-8142
- EPSS 88.28%
- Veröffentlicht 20.12.2014 11:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call th...
CVE-2014-8626
- EPSS 3.95%
- Veröffentlicht 23.11.2014 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone fie...
- EPSS 10.21%
- Veröffentlicht 05.11.2014 11:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and appli...
- EPSS 1.15%
- Veröffentlicht 29.10.2014 10:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (app...
CVE-2014-3669
- EPSS 66.58%
- Veröffentlicht 29.10.2014 10:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...