Записи pear
22 опубликованных записей вендора pear.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 72,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG)1
- CWE-624 Executable Regular Expression Error1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-783 Operator Precedence Logic Error1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2009-4025Эксплойта нет | Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows repear · pear · CWE-78 | Критическая10,0 | — | 6,1 % | 29 нояб. 2009 г. |
42В плане | CVE-2009-4024Эксплойта нет | Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to epear · pear · CWE-94 | Критическая10,0 | — | 6,1 % | 29 нояб. 2009 г. |
40В плане | CVE-2017-5677Эксплойта нет | PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.pear · html ajax | Критическая9,8 | — | 4,8 % | 6 февр. 2017 г. |
40В плане | CVE-2005-4730Эксплойта нет | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nupear · text password | Критическая10,0 | — | 1,4 % | 31 дек. 2005 г. |
37Наблюдать | CVE-2026-25241Эксплойта нет | PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpointpear · pearweb · CWE-89 | Критическая9,3 | — | 0,4 % | 3 февр. 2026 г. |
36Наблюдать | CVE-2026-25237Эксплойта нет | PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emailspear · pearweb · CWE-624 | Критическая9,2 | — | 0,4 % | 3 февр. 2026 г. |
36Наблюдать | CVE-2026-25238Эксплойта нет | PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validationpear · pearweb · CWE-89 | Критическая9,2 | — | 0,3 % | 3 февр. 2026 г. |
32Наблюдать | CVE-2026-25235Эксплойта нет | PEAR Has a Predictable Verification Hash in Election Account Requestspear · pearweb · CWE-337 | Высокая8,2 | — | 0,3 % | 3 февр. 2026 г. |
32Наблюдать | CVE-2026-25239Эксплойта нет | PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filenamepear · pearweb · CWE-89 | Высокая8,2 | — | 0,2 % | 3 февр. 2026 г. |
31Наблюдать | CVE-2006-0868Эксплойта нет | Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4pear · xml rpc | Высокая7,5 | — | 2,5 % | 23 февр. 2006 г. |
31Наблюдать | CVE-2009-4023Эксплойта нет | Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for pear · pear · CWE-94 | Высокая7,5 | — | 2,4 % | 29 нояб. 2009 г. |
28Наблюдать | CVE-2026-25233Эксплойта нет | PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bugpear · pearweb · CWE-783 | Высокая7,1 | — | 0,3 % | 3 февр. 2026 г. |
27Наблюдать | CVE-2009-4111Эксплойта нет | Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remotpear · mail · CWE-94 | Средняя6,8 | — | 1,6 % | 29 нояб. 2009 г. |
27Наблюдать | CVE-2026-25240Эксплойта нет | PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filterpear · pearweb · CWE-89 | Средняя6,9 | — | 0,3 % | 3 февр. 2026 г. |
27Наблюдать | CVE-2026-25236Эксплойта нет | PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitutionpear · pearweb · CWE-89 | Средняя6,9 | — | 0,3 % | 3 февр. 2026 г. |
26Наблюдать | CVE-2006-0869Proof of concept | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0pear · pear liveuser | Средняя6,4 | — | 4,0 % | 23 февр. 2006 г. |
21Наблюдать | CVE-2006-0931Эксплойта нет | Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwritepear · pear archive tar · CWE-22 | Средняя5,0 | — | 2,4 % | 28 февр. 2006 г. |
21Наблюдать | CVE-2006-0932Эксплойта нет | Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files pear · pear archive zip | Средняя5,0 | — | 1,9 % | 28 февр. 2006 г. |
21Наблюдать | CVE-2022-24953Эксплойта нет | The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environmentpear · crypt gpg · CWE-88 | Средняя5,3 | — | 0,9 % | 17 февр. 2022 г. |
21Наблюдать | CVE-2026-25234Эксплойта нет | PEAR is Vulnerable to SQL Injection in Category Deletionpear · pearweb · CWE-89 | Средняя5,3 | — | 0,3 % | 3 февр. 2026 г. |
20Наблюдать | CVE-2007-3628Эксплойта нет | Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers tpear · structures datagrid datasource mdb2 | Средняя5,0 | — | 1,0 % | 9 июл. 2007 г. |
17Наблюдать | CVE-2007-5934Эксплойта нет | The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contentspear · structures datagrid datasource mdb2 · CWE-200 | Средняя4,3 | — | 1,6 % | 13 нояб. 2007 г. |
- CVE-2009-402542В плане
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows re
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %pear · pear29 нояб. 2009 г.
- CVE-2009-402442В плане
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to e
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %pear · pear29 нояб. 2009 г.
- CVE-2017-567740В плане
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pear · html ajax6 февр. 2017 г.
- CVE-2005-473040В плане
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nu
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %pear · text password31 дек. 2005 г.
- CVE-2026-2524137Наблюдать
PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpoint
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2026-2523736Наблюдать
PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2026-2523836Наблюдать
PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validation
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2026-2523532Наблюдать
PEAR Has a Predictable Verification Hash in Election Account Requests
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2026-2523932Наблюдать
PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filename
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2006-086831Наблюдать
Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %pear · xml rpc23 февр. 2006 г.
- CVE-2009-402331Наблюдать
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %pear · pear29 нояб. 2009 г.
- CVE-2026-2523328Наблюдать
PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2009-411127Наблюдать
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remot
СредняяCVSS 6,8Эксплойта нетEPSS 2 %pear · mail29 нояб. 2009 г.
- CVE-2026-2524027Наблюдать
PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filter
СредняяCVSS 6,9Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2026-2523627Наблюдать
PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitution
СредняяCVSS 6,9Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2006-086926Наблюдать
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0
СредняяCVSS 6,4Proof of conceptEPSS 4 %pear · pear liveuser23 февр. 2006 г.
- CVE-2006-093121Наблюдать
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite
СредняяCVSS 5,0Эксплойта нетEPSS 2 %pear · pear archive tar28 февр. 2006 г.
- CVE-2006-093221Наблюдать
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files
СредняяCVSS 5,0Эксплойта нетEPSS 2 %pear · pear archive zip28 февр. 2006 г.
- CVE-2022-2495321Наблюдать
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environment
СредняяCVSS 5,3Эксплойта нетEPSS 1 %pear · crypt gpg17 февр. 2022 г.
- CVE-2026-2523421Наблюдать
PEAR is Vulnerable to SQL Injection in Category Deletion
СредняяCVSS 5,3Эксплойта нетEPSS 0 %pear · pearweb3 февр. 2026 г.
- CVE-2007-362820Наблюдать
Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers t
СредняяCVSS 5,0Эксплойта нетEPSS 1 %pear · structures datagrid datasource mdb29 июл. 2007 г.
- CVE-2007-593417Наблюдать
The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents
СредняяCVSS 4,3Эксплойта нетEPSS 2 %pear · structures datagrid datasource mdb213 нояб. 2007 г.