Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.66%
  • Veröffentlicht 24.04.2015 17:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other im...

Exploit
  • EPSS 12.22%
  • Veröffentlicht 30.03.2015 10:59:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call th...

Exploit
  • EPSS 8.59%
  • Veröffentlicht 30.03.2015 10:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extens...

Exploit
  • EPSS 27.69%
  • Veröffentlicht 30.03.2015 10:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial ...

Exploit
  • EPSS 8.34%
  • Veröffentlicht 30.03.2015 10:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary co...

Exploit
  • EPSS 14.67%
  • Veröffentlicht 30.03.2015 10:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...

Exploit
  • EPSS 7.7%
  • Veröffentlicht 30.03.2015 10:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The build_tablename function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP through 5.6.7 does not validate token extraction for table names, which allows remote attackers to cause a denial of service (NULL pointer dereference and applicat...

Exploit
  • EPSS 8.65%
  • Veröffentlicht 30.03.2015 10:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Exploit
  • EPSS 42.91%
  • Veröffentlicht 30.03.2015 10:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier ...

Exploit
  • EPSS 15.43%
  • Veröffentlicht 30.03.2015 10:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperl...