Php

Php

711 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.1%
  • Published 18.01.2011 20:00:10
  • Last modified 11.04.2025 00:51:21

PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argum...

  • EPSS 1.39%
  • Published 18.01.2011 20:00:10
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of _...

  • EPSS 8.91%
  • Published 18.01.2011 20:00:10
  • Last modified 11.04.2025 00:51:21

Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstex...

  • EPSS 0.16%
  • Published 18.01.2011 20:00:10
  • Last modified 11.04.2025 00:51:21

The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an i...

  • EPSS 0.24%
  • Published 18.01.2011 20:00:10
  • Last modified 11.04.2025 00:51:21

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injecti...

Exploit
  • EPSS 21.55%
  • Published 11.01.2011 03:00:04
  • Last modified 11.04.2025 00:51:21

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation...

  • EPSS 16.66%
  • Published 07.12.2010 22:00:02
  • Last modified 11.04.2025 00:51:21

Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via ...

  • EPSS 31.59%
  • Published 06.12.2010 20:13:00
  • Last modified 11.04.2025 00:51:21

Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument.

Exploit
  • EPSS 2.98%
  • Published 12.11.2010 22:00:01
  • Last modified 11.04.2025 00:51:21

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 enc...

Exploit
  • EPSS 0.85%
  • Published 12.11.2010 21:00:02
  • Last modified 11.04.2025 00:51:21

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protec...