Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 53.17%
  • Veröffentlicht 20.12.2014 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call th...

Exploit
  • EPSS 5.78%
  • Veröffentlicht 23.11.2014 02:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone fie...

  • EPSS 14.01%
  • Veröffentlicht 05.11.2014 11:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and appli...

Exploit
  • EPSS 27.02%
  • Veröffentlicht 29.10.2014 10:55:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (app...

Exploit
  • EPSS 28.86%
  • Veröffentlicht 29.10.2014 10:55:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...

Exploit
  • EPSS 22.63%
  • Veröffentlicht 29.10.2014 10:55:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory ...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 27.09.2014 10:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache...

  • EPSS 15.43%
  • Veröffentlicht 23.08.2014 01:55:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted DNS re...

  • EPSS 16.93%
  • Veröffentlicht 23.08.2014 01:55:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) ...

Exploit
  • EPSS 20.24%
  • Veröffentlicht 23.08.2014 01:55:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a craf...