CVE-2015-3414
- EPSS 4.66%
- Veröffentlicht 24.04.2015 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other im...
CVE-2015-2787
- EPSS 12.22%
- Veröffentlicht 30.03.2015 10:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call th...
- EPSS 8.59%
- Veröffentlicht 30.03.2015 10:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extens...
CVE-2015-2331
- EPSS 27.69%
- Veröffentlicht 30.03.2015 10:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial ...
CVE-2015-2305
- EPSS 8.34%
- Veröffentlicht 30.03.2015 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary co...
CVE-2015-2301
- EPSS 14.67%
- Veröffentlicht 30.03.2015 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...
- EPSS 7.7%
- Veröffentlicht 30.03.2015 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and applicat...
CVE-2015-1351
- EPSS 8.65%
- Veröffentlicht 30.03.2015 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2015-0273
- EPSS 42.91%
- Veröffentlicht 30.03.2015 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier ...
- EPSS 15.43%
- Veröffentlicht 30.03.2015 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperl...