Skip to content
Noroxi

php records

781 published records for vendor php.

Researcher profile

Entered KEV
5 · 0.6%
Weaponized
11 · 1.4%
Pre-auth RCE
165
With a fix record
70%
Median publish → KEV
644 days

All records

781 records
  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Argument Injection in PHP-CGI

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpJun 9, 2024

  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    HighCVSS 7.8KEVWeaponizedEPSS 85%

    php · archive tarNov 19, 2020

  • Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat

    HighCVSS 7.5KEVWeaponizedEPSS 71%

    php · archive tarJan 18, 2021

  • CVE-2015-0235
    68This week

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    CriticalCVSS 10.0WeaponizedEPSS 95%

    gnu · glibcJan 28, 2015

  • CVE-2018-7584
    65This week

    In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while pa

    CriticalCVSS 9.8Proof of conceptEPSS 87%

    php · phpMar 1, 2018

  • University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of

    HighCVSS 7.5WeaponizedEPSS 96%

    php · phpNov 25, 2018

  • gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.

    HighCVSS 8.8Proof of conceptEPSS 71%

    libgd · libgdJan 26, 2019

  • Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-b

    CriticalCVSS 9.8Proof of conceptEPSS 56%

    php · phpAug 7, 2016

  • Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1

    HighCVSS 7.5WeaponizedEPSS 79%

    php · xml rpcJul 5, 2005

  • Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute

    CriticalCVSS 9.8Proof of conceptEPSS 47%

    php · phpMay 16, 2016

  • mysqlnd/pdo password buffer overflow

    HighCVSS 8.8Proof of conceptEPSS 58%

    php · phpJun 16, 2022

  • In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-af

    CriticalCVSS 9.8No exploitEPSS 42%

    php · phpJan 11, 2017

  • sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle que

    HighCVSS 7.5Proof of conceptEPSS 69%

    php · phpMay 11, 2012

  • The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whic

    CriticalCVSS 9.8No exploitEPSS 42%

    php · phpJan 11, 2017

  • In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

    HighCVSS 7.1No exploitEPSS 73%

    php · archive tarJul 30, 2021

  • The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to mod

    HighCVSS 7.5Proof of conceptEPSS 66%

    php · phpNov 1, 2005

  • Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or

    CriticalCVSS 9.8Proof of conceptEPSS 37%

    libgd · libgdApr 26, 2016

  • The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, w

    CriticalCVSS 9.8Proof of conceptEPSS 36%

    php · phpMay 16, 2016

  • Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a

    CriticalCVSS 9.8Proof of conceptEPSS 36%

    php · phpMar 31, 2016

  • PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arb

    CriticalCVSS 10.0No exploitEPSS 31%

    php · phpAug 6, 2004

  • An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.

    MediumCVSS 6.1No exploitEPSS 80%

    php · phpJan 16, 2018

  • PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t

    HighCVSS 8.1No exploitEPSS 50%

    hp · storeever msl6480 tape library firmwareJul 18, 2016

  • Command injection via array-ish $command parameter of proc_open()

    CriticalCVSS 9.4Proof of conceptEPSS 33%

    php · phpApr 29, 2024