Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.91%
  • Veröffentlicht 18.06.2014 19:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns...

  • EPSS 0.78%
  • Veröffentlicht 08.06.2014 18:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

  • EPSS 19.88%
  • Veröffentlicht 01.06.2014 04:29:34
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

  • EPSS 20.81%
  • Veröffentlicht 01.06.2014 04:29:34
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero len...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 06.05.2014 10:44:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

Exploit
  • EPSS 3.04%
  • Veröffentlicht 24.03.2014 16:31:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a cra...

Exploit
  • EPSS 22.32%
  • Veröffentlicht 21.03.2014 14:55:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

  • EPSS 4.32%
  • Veröffentlicht 14.03.2014 15:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

  • EPSS 5.03%
  • Veröffentlicht 18.02.2014 19:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

  • EPSS 2.53%
  • Veröffentlicht 18.02.2014 11:55:17
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function...