Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 29.03.2011 18:55:01
  • Zuletzt bearbeitet 16.06.2026 23:27:23

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

Exploit
  • EPSS 2.8%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:23

Buffer overflow in the strval function in PHP before 5.3.6, when the precision configuration option has a large value, might allow context-dependent attackers to cause a denial of service (application crash) via a small numerical value in the argumen...

Exploit
  • EPSS 5.86%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:23

Integer overflow in the SdnToJulian function in the Calendar extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a large integer in the first argument to the cal_from_jd function.

  • EPSS 12.72%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:24

Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a rela...

Exploit
  • EPSS 13.26%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:24

Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via (1) plaintext data to the openssl_encrypt function or (2) ciphertext data to the openssl_decrypt fun...

Exploit
  • EPSS 4.34%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:24

Unspecified vulnerability in the Streams component in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) by accessing an ftp:// URL during use of an HTTP proxy with the FTP wrapper.

Exploit
  • EPSS 9.52%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:24

The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that is not properly handled by the stream_get_contents function.

Exploit
  • EPSS 13.19%
  • Veröffentlicht 20.03.2011 02:00:04
  • Zuletzt bearbeitet 16.06.2026 23:29:24

Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

Exploit
  • EPSS 13.51%
  • Veröffentlicht 20.03.2011 02:00:03
  • Zuletzt bearbeitet 16.06.2026 23:27:19

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer derefer...

Exploit
  • EPSS 9.83%
  • Veröffentlicht 20.03.2011 02:00:03
  • Zuletzt bearbeitet 16.06.2026 23:27:55

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buf...