Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 11.18%
  • Veröffentlicht 06.08.2012 16:55:05
  • Zuletzt bearbeitet 16.06.2026 23:43:14

pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bound...

  • EPSS 2.98%
  • Veröffentlicht 20.07.2012 10:40:37
  • Zuletzt bearbeitet 16.06.2026 23:43:04

The SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors.

  • EPSS 10.47%
  • Veröffentlicht 20.07.2012 10:40:36
  • Zuletzt bearbeitet 16.06.2026 23:41:53

Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."

Exploit
  • EPSS 42.48%
  • Veröffentlicht 07.07.2012 10:21:13
  • Zuletzt bearbeitet 16.06.2026 23:41:27

Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted t...

  • EPSS 5.73%
  • Veröffentlicht 05.07.2012 14:55:02
  • Zuletzt bearbeitet 16.06.2026 23:41:04

The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for cont...

Exploit
  • EPSS 6.37%
  • Veröffentlicht 24.05.2012 00:55:02
  • Zuletzt bearbeitet 16.06.2026 23:39:10

The file-upload implementation in rfc1867.c in PHP before 5.4.0 does not properly handle invalid [ (open square bracket) characters in name values, which makes it easier for remote attackers to cause a denial of service (malformed $_FILES indexes) or...

Exploit
  • EPSS 20.05%
  • Veröffentlicht 21.05.2012 15:55:02
  • Zuletzt bearbeitet 16.06.2026 23:41:26

Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments that trigger incorrect handling of COM object VARIANT types, as exploited in the wild in Ma...

Warnung Exploit
  • EPSS 100%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 16.06.2026 23:40:22

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...

  • EPSS 69.56%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 16.06.2026 23:41:20

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to exec...

  • EPSS 62.65%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 16.06.2026 23:41:22

Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote attackers to cause a denial of service (application crash) via a long string in the header of an HTTP request.