Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 19.2%
  • Veröffentlicht 30.03.2015 10:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of m...

  • EPSS 4.65%
  • Veröffentlicht 30.03.2015 10:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers t...

  • EPSS 5.45%
  • Veröffentlicht 30.03.2015 10:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version...

  • EPSS 0.58%
  • Veröffentlicht 30.03.2015 10:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp wit...

  • EPSS 94.86%
  • Veröffentlicht 28.01.2015 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...

Exploit
  • EPSS 16.21%
  • Veröffentlicht 27.01.2015 20:04:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) v...

Exploit
  • EPSS 42.59%
  • Veröffentlicht 27.01.2015 20:03:41
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call th...

Exploit
  • EPSS 17.34%
  • Veröffentlicht 03.01.2015 02:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length during processing of an invalid file that begins wit...

  • EPSS 2.14%
  • Veröffentlicht 31.12.2014 02:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The apprentice_load function in libmagic/apprentice.c in the Fileinfo component in PHP through 5.6.4 attempts to perform a free operation on a stack-based character array, which allows remote attackers to cause a denial of service (memory corruption ...

  • EPSS 3.66%
  • Veröffentlicht 31.12.2014 02:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact ...