Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.5%
  • Veröffentlicht 21.12.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:13:07

The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks b...

  • EPSS 2.95%
  • Veröffentlicht 21.12.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:13:07

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

Exploit
  • EPSS 8.31%
  • Veröffentlicht 01.12.2009 16:30:01
  • Zuletzt bearbeitet 16.06.2026 23:09:52

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a varia...

Exploit
  • EPSS 11.34%
  • Veröffentlicht 29.11.2009 13:07:32
  • Zuletzt bearbeitet 16.06.2026 23:12:50

The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute pr...

  • EPSS 12.04%
  • Veröffentlicht 24.11.2009 00:30:00
  • Zuletzt bearbeitet 16.06.2026 23:12:50

PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier f...

Exploit
  • EPSS 2.1%
  • Veröffentlicht 23.11.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:51

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix argu...

Exploit
  • EPSS 2.08%
  • Veröffentlicht 23.11.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:51

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating...

  • EPSS 2.7%
  • Veröffentlicht 23.11.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:51

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require...

  • EPSS 10.21%
  • Veröffentlicht 19.10.2009 20:00:00
  • Zuletzt bearbeitet 16.06.2026 23:11:49

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-...

  • EPSS 2.91%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:19

The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.