Php

Php

739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.78%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:19

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

  • EPSS 2.69%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:19

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

Exploit
  • EPSS 2.73%
  • Veröffentlicht 22.09.2009 10:30:00
  • Zuletzt bearbeitet 16.06.2026 23:11:19

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" stri...

Exploit
  • EPSS 1.59%
  • Veröffentlicht 25.08.2009 10:30:00
  • Zuletzt bearbeitet 16.06.2026 23:03:32

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 19.08.2009 05:24:52
  • Zuletzt bearbeitet 16.06.2026 23:03:24

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) ...

Exploit
  • EPSS 4.38%
  • Veröffentlicht 05.08.2009 19:30:01
  • Zuletzt bearbeitet 16.06.2026 23:10:00

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

  • EPSS 2.4%
  • Veröffentlicht 08.04.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:54

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

  • EPSS 1.97%
  • Veröffentlicht 08.04.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:55

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during ex...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 03.03.2009 16:30:05
  • Zuletzt bearbeitet 16.06.2026 23:05:44

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied...

Exploit
  • EPSS 1.66%
  • Veröffentlicht 05.01.2009 20:30:02
  • Zuletzt bearbeitet 16.06.2026 23:01:05

PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL ...