Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.52%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 16.06.2026 23:25:22

Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstex...

  • EPSS 1.63%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 16.06.2026 23:25:22

The iconv_mime_decode_headers function in the Iconv extension in PHP before 5.3.4 does not properly handle encodings that are unrecognized by the iconv and mbstring (aka Multibyte String) implementations, which allows remote attackers to trigger an i...

  • EPSS 1.46%
  • Veröffentlicht 18.01.2011 20:00:10
  • Zuletzt bearbeitet 16.06.2026 23:25:22

The set_magic_quotes_runtime function in PHP 5.3.2 and 5.3.3, when the MySQLi extension is used, does not properly interact with use of the mysqli_fetch_assoc function, which might make it easier for context-dependent attackers to conduct SQL injecti...

Exploit
  • EPSS 15.1%
  • Veröffentlicht 11.01.2011 03:00:04
  • Zuletzt bearbeitet 16.06.2026 23:25:14

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation...

  • EPSS 6.01%
  • Veröffentlicht 07.12.2010 22:00:02
  • Zuletzt bearbeitet 16.06.2026 23:24:12

Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via ...

  • EPSS 18.88%
  • Veröffentlicht 06.12.2010 20:13:00
  • Zuletzt bearbeitet 16.06.2026 23:24:44

Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument.

Exploit
  • EPSS 2.65%
  • Veröffentlicht 12.11.2010 22:00:01
  • Zuletzt bearbeitet 16.06.2026 23:14:49

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 enc...

Exploit
  • EPSS 11.28%
  • Veröffentlicht 12.11.2010 21:00:02
  • Zuletzt bearbeitet 16.06.2026 23:23:43

The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protec...

  • EPSS 6.32%
  • Veröffentlicht 09.11.2010 01:00:02
  • Zuletzt bearbeitet 16.06.2026 23:22:46

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.

Exploit
  • EPSS 13.33%
  • Veröffentlicht 09.11.2010 01:00:02
  • Zuletzt bearbeitet 16.06.2026 23:23:23

The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.