Php

Php

711 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.6%
  • Veröffentlicht 18.01.2012 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup ...

  • EPSS 88.58%
  • Veröffentlicht 30.12.2011 01:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Exploit
  • EPSS 55.85%
  • Veröffentlicht 29.11.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_v...

Exploit
  • EPSS 1.09%
  • Veröffentlicht 03.11.2011 15:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages a...

  • EPSS 4.18%
  • Veröffentlicht 25.08.2011 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

  • EPSS 19.37%
  • Veröffentlicht 25.08.2011 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

Exploit
  • EPSS 1.37%
  • Veröffentlicht 25.08.2011 14:22:48
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability tha...

Exploit
  • EPSS 1.66%
  • Veröffentlicht 25.08.2011 14:22:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffe...

Exploit
  • EPSS 13.12%
  • Veröffentlicht 25.08.2011 14:22:44
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRF...

  • EPSS 8.27%
  • Veröffentlicht 25.08.2011 14:22:44
  • Zuletzt bearbeitet 11.04.2025 00:51:21

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext passwo...