Php

Php

714 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.02%
  • Veröffentlicht 01.04.2020 04:15:13
  • Zuletzt bearbeitet 21.11.2024 05:36:36

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and pote...

Exploit
  • EPSS 1.16%
  • Veröffentlicht 27.02.2020 21:15:19
  • Zuletzt bearbeitet 21.11.2024 05:36:35

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upl...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 27.02.2020 21:15:19
  • Zuletzt bearbeitet 21.11.2024 05:36:35

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on th...

Exploit
  • EPSS 2.06%
  • Veröffentlicht 27.02.2020 21:15:18
  • Zuletzt bearbeitet 21.11.2024 05:36:35

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information ...

Exploit
  • EPSS 1.95%
  • Veröffentlicht 19.02.2020 13:15:10
  • Zuletzt bearbeitet 21.11.2024 02:08:31

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

Exploit
  • EPSS 24.64%
  • Veröffentlicht 12.02.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 01:30:17

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

Exploit
  • EPSS 2.37%
  • Veröffentlicht 10.02.2020 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:35

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead t...

Exploit
  • EPSS 6.4%
  • Veröffentlicht 10.02.2020 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:35

When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the alloc...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 14.01.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 02:27:13

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a gro...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 14.01.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 02:27:13

The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call a...