Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.23%
  • Veröffentlicht 21.06.2013 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish ...

  • EPSS 1.98%
  • Veröffentlicht 21.06.2013 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type ...

  • EPSS 6.75%
  • Veröffentlicht 21.06.2013 20:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Heap-based buffer overflow in the php_quot_print_encode function in ext/standard/quot_print.c in PHP before 5.3.26 and 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other imp...

Exploit
  • EPSS 2.83%
  • Veröffentlicht 31.05.2013 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafte...

  • EPSS 9.75%
  • Veröffentlicht 06.03.2013 13:10:27
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggeri...

  • EPSS 10.14%
  • Veröffentlicht 06.03.2013 13:10:27
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity...

  • EPSS 2.54%
  • Veröffentlicht 19.01.2013 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 11.10.2012 10:51:57
  • Zuletzt bearbeitet 16.06.2026 23:46:46

Untrusted search path vulnerability in the installation functionality in PHP 5.3.17, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\PHP directory, which may be added to the P...

Exploit
  • EPSS 4.23%
  • Veröffentlicht 07.09.2012 22:55:02
  • Zuletzt bearbeitet 16.06.2026 23:44:55

The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protec...

  • EPSS 10.17%
  • Veröffentlicht 30.08.2012 22:55:02
  • Zuletzt bearbeitet 16.06.2026 23:29:16

The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a...