Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.16%
  • Veröffentlicht 25.08.2011 14:22:47
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffe...

Exploit
  • EPSS 10.67%
  • Veröffentlicht 25.08.2011 14:22:44
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRF...

  • EPSS 6.5%
  • Veröffentlicht 25.08.2011 14:22:44
  • Zuletzt bearbeitet 11.04.2025 00:51:21

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext passwo...

Exploit
  • EPSS 21.69%
  • Veröffentlicht 16.06.2011 23:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwr...

Exploit
  • EPSS 37.26%
  • Veröffentlicht 31.05.2011 20:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.

  • EPSS 0.03%
  • Veröffentlicht 29.03.2011 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the strval function in PHP before 5.3.6, when the precision configuration option has a large value, might allow context-dependent attackers to cause a denial of service (application crash) via a small numerical value in the argumen...

Exploit
  • EPSS 26.12%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the SdnToJulian function in the Calendar extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a large integer in the first argument to the cal_from_jd function.

  • EPSS 6.3%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a rela...

Exploit
  • EPSS 6.83%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via (1) plaintext data to the openssl_encrypt function or (2) ciphertext data to the openssl_decrypt fun...