Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.26%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 04.12.2025 21:16:06

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 19.44%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...

  • EPSS 60.79%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that...

Exploit
  • EPSS 8.65%
  • Veröffentlicht 06.07.2014 23:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent ...

Exploit
  • EPSS 10.25%
  • Veröffentlicht 03.07.2014 14:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. N...

  • EPSS 17.79%
  • Veröffentlicht 18.06.2014 19:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns...

  • EPSS 0.26%
  • Veröffentlicht 08.06.2014 18:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

  • EPSS 38.24%
  • Veröffentlicht 01.06.2014 04:29:34
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

  • EPSS 26.16%
  • Veröffentlicht 01.06.2014 04:29:34
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero len...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 06.05.2014 10:44:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.