Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1%
  • Veröffentlicht 07.05.2010 23:00:01
  • Zuletzt bearbeitet 16.06.2026 23:19:28

The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object's __sleep function to interrupt an internal call to the shm_put_var function, which tr...

Exploit
  • EPSS 1.19%
  • Veröffentlicht 07.05.2010 23:00:01
  • Zuletzt bearbeitet 16.06.2026 23:19:28

The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass b...

Exploit
  • EPSS 1.19%
  • Veröffentlicht 07.05.2010 23:00:01
  • Zuletzt bearbeitet 16.06.2026 23:19:28

The addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass b...

Exploit
  • EPSS 6.72%
  • Veröffentlicht 07.05.2010 23:00:01
  • Zuletzt bearbeitet 16.06.2026 23:19:29

The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a sig...

Exploit
  • EPSS 3.03%
  • Veröffentlicht 07.05.2010 23:00:01
  • Zuletzt bearbeitet 16.06.2026 23:19:29

The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, wh...

Exploit
  • EPSS 7.94%
  • Veröffentlicht 26.03.2010 20:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:34

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies gener...

  • EPSS 2.54%
  • Veröffentlicht 26.03.2010 20:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:34

The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the...

Exploit
  • EPSS 9.37%
  • Veröffentlicht 26.03.2010 20:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:34

session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode ...

Exploit
  • EPSS 11.53%
  • Veröffentlicht 16.03.2010 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:16:04

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and a...

  • EPSS 0.97%
  • Veröffentlicht 24.12.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:13:37

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: s...