Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.68%
  • Veröffentlicht 10.07.2014 11:06:29
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applicatio...

  • EPSS 0.71%
  • Veröffentlicht 10.07.2014 11:06:28
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications i...

  • EPSS 16.85%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...

Exploit
  • EPSS 15.18%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal...

  • EPSS 14.93%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 11.48%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 14.93%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...

  • EPSS 30.13%
  • Veröffentlicht 09.07.2014 11:07:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that...

Exploit
  • EPSS 5.87%
  • Veröffentlicht 06.07.2014 23:55:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent ...

Exploit
  • EPSS 11.81%
  • Veröffentlicht 03.07.2014 14:55:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. N...