Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.5%
  • Veröffentlicht 23.11.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix argu...

Exploit
  • EPSS 4.44%
  • Veröffentlicht 23.11.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating...

  • EPSS 2.9%
  • Veröffentlicht 23.11.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require...

  • EPSS 4.13%
  • Veröffentlicht 19.10.2009 20:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-...

  • EPSS 2.21%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

  • EPSS 3.61%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

  • EPSS 1.81%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

Exploit
  • EPSS 1.89%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" stri...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 25.08.2009 10:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 19.08.2009 05:24:52
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) ...