Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 32.54%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 16.06.2026 23:41:23

php-wrapper.fcgi does not properly handle command-line arguments, which allows remote attackers to bypass a protection mechanism in PHP 5.3.12 and 5.4.2 and execute arbitrary code by leveraging improper interaction between the PHP sapi/cgi/cgi_main.c...

  • EPSS 50.72%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 16.06.2026 23:41:23

sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to cause a denial of service ...

  • EPSS 8.95%
  • Veröffentlicht 14.02.2012 15:55:00
  • Zuletzt bearbeitet 16.06.2026 23:38:15

The PDORow implementation in PHP before 5.3.9 does not properly interact with the session feature, which allows remote attackers to cause a denial of service (application crash) via a crafted application that uses a PDO driver for a fetch and then ca...

Exploit
  • EPSS 8.26%
  • Veröffentlicht 14.02.2012 15:55:00
  • Zuletzt bearbeitet 16.06.2026 23:38:15

Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memory consumption) by triggering many strtotime function calls, which are not properly handled by the php_date_parse_tzfile cache.

Exploit
  • EPSS 6.71%
  • Veröffentlicht 10.02.2012 20:55:02
  • Zuletzt bearbeitet 16.06.2026 23:38:20

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related...

Exploit
  • EPSS 30.14%
  • Veröffentlicht 06.02.2012 20:55:03
  • Zuletzt bearbeitet 16.06.2026 23:38:20

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability e...

  • EPSS 3.15%
  • Veröffentlicht 02.02.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:36:35

PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.

Exploit
  • EPSS 10.77%
  • Veröffentlicht 18.01.2012 20:55:03
  • Zuletzt bearbeitet 16.06.2026 23:38:15

The tidy_diagnose function in PHP 5.3.8 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that attempts to perform Tidy::diagnose operations on invalid objec...

Exploit
  • EPSS 12.2%
  • Veröffentlicht 18.01.2012 20:55:02
  • Zuletzt bearbeitet 16.06.2026 23:34:30

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup ...

  • EPSS 83.37%
  • Veröffentlicht 30.12.2011 01:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:34

PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.