Php

Php

711 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 8.34%
  • Veröffentlicht 23.08.2014 01:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) ...

Exploit
  • EPSS 18.72%
  • Veröffentlicht 23.08.2014 01:55:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a craf...

  • EPSS 0.49%
  • Veröffentlicht 10.07.2014 11:06:29
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applicatio...

  • EPSS 0.34%
  • Veröffentlicht 10.07.2014 11:06:28
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications i...

  • EPSS 8.85%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...

Exploit
  • EPSS 43.75%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal...

  • EPSS 11.28%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 11.28%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 18.5%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...

  • EPSS 37.41%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that...