Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 20.08.2010 20:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that caus...

  • EPSS 1.09%
  • Veröffentlicht 20.08.2010 20:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username o...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 20.08.2010 20:00:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

Exploit
  • EPSS 2.19%
  • Veröffentlicht 24.06.2010 12:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.

Exploit
  • EPSS 0.56%
  • Veröffentlicht 08.06.2010 00:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an interna...

Exploit
  • EPSS 1.26%
  • Veröffentlicht 08.06.2010 00:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-de...

Exploit
  • EPSS 0.92%
  • Veröffentlicht 27.05.2010 22:30:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) http_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents)...

Exploit
  • EPSS 1.12%
  • Veröffentlicht 27.05.2010 22:30:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing ...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 27.05.2010 22:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction o...

Exploit
  • EPSS 3.09%
  • Veröffentlicht 27.05.2010 22:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properl...