CVE-2025-1219
- EPSS 0.07%
- Veröffentlicht 30.03.2025 06:15:13
- Zuletzt bearbeitet 03.11.2025 21:18:52
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when t...
CVE-2025-1217
- EPSS 0.1%
- Veröffentlicht 29.03.2025 05:19:33
- Zuletzt bearbeitet 03.11.2025 21:18:52
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreti...
CVE-2022-31631
- EPSS 0.78%
- Veröffentlicht 12.02.2025 22:15:29
- Zuletzt bearbeitet 02.07.2025 21:35:56
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may furthe...
CVE-2024-2756
- EPSS 9.76%
- Veröffentlicht 29.04.2024 04:15:07
- Zuletzt bearbeitet 04.11.2025 18:16:18
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applic...
- EPSS 0.59%
- Veröffentlicht 24.05.2007 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value.
CVE-2006-3016
- EPSS 6.74%
- Veröffentlicht 14.06.2006 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters that are frequently associated with CRLF injection, SQL injection, cross-...
CVE-2006-3018
- EPSS 1.17%
- Veröffentlicht 14.06.2006 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.