CVE-2012-2335
- EPSS 32.54%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 16.06.2026 23:41:23
php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c...
- EPSS 50.72%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 16.06.2026 23:41:23
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service ...
- EPSS 8.95%
- Veröffentlicht 14.02.2012 15:55:00
- Zuletzt bearbeitet 16.06.2026 23:38:15
The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then ca...
- EPSS 8.26%
- Veröffentlicht 14.02.2012 15:55:00
- Zuletzt bearbeitet 16.06.2026 23:38:15
Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.
CVE-2012-0831
- EPSS 6.71%
- Veröffentlicht 10.02.2012 20:55:02
- Zuletzt bearbeitet 16.06.2026 23:38:20
PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related...
CVE-2012-0830
- EPSS 30.14%
- Veröffentlicht 06.02.2012 20:55:03
- Zuletzt bearbeitet 16.06.2026 23:38:20
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability e...
CVE-2012-0057
- EPSS 3.15%
- Veröffentlicht 02.02.2012 00:55:01
- Zuletzt bearbeitet 16.06.2026 23:36:35
PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.
- EPSS 10.77%
- Veröffentlicht 18.01.2012 20:55:03
- Zuletzt bearbeitet 16.06.2026 23:38:15
The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that attempts to perform Tidy::diagnose operations on invalid objec...
- EPSS 12.2%
- Veröffentlicht 18.01.2012 20:55:02
- Zuletzt bearbeitet 16.06.2026 23:34:30
PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup ...
- EPSS 83.37%
- Veröffentlicht 30.12.2011 01:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:34
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.