Перейти к содержимому
Noroxi

Записи php

781 опубликованных записей вендора php.

Профиль для исследователя

Попали в KEV
5 · 0,6 %
С эксплойтом
11 · 1,4 %
Pre-auth RCE
165
С записью об исправлении
70 %
Медиана: публикация → KEV
644 дн.

Все записи

781 записей
  • CVE-2012-1823
    99Срочно

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php11 мая 2012 г.

  • CVE-2024-4577
    99Срочно

    Argument Injection in PHP-CGI

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php9 июн. 2024 г.

  • CVE-2019-11043
    99Срочно

    Underflow in PHP-FPM can lead to RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    php · php28 окт. 2019 г.

  • CVE-2020-28949
    86Срочно

    Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 85 %

    php · archive tar19 нояб. 2020 г.

  • CVE-2020-36193
    81Срочно

    Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 71 %

    php · archive tar18 янв. 2021 г.

  • CVE-2015-0235
    68На этой неделе

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %

    gnu · glibc28 янв. 2015 г.

  • CVE-2018-7584
    65На этой неделе

    In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while pa

    КритическаяCVSS 9,8Proof of conceptEPSS 87 %

    php · php1 мар. 2018 г.

  • CVE-2018-19518
    59В плане

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 96 %

    php · php25 нояб. 2018 г.

  • CVE-2019-6977
    56В плане

    gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.

    ВысокаяCVSS 8,8Proof of conceptEPSS 71 %

    libgd · libgd26 янв. 2019 г.

  • CVE-2016-3078
    56В плане

    Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-b

    КритическаяCVSS 9,8Proof of conceptEPSS 56 %

    php · php7 авг. 2016 г.

  • CVE-2005-1921
    54В плане

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %

    php · xml rpc5 июл. 2005 г.

  • CVE-2015-6834
    53В плане

    Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute

    КритическаяCVSS 9,8Proof of conceptEPSS 47 %

    php · php16 мая 2016 г.

  • CVE-2022-31626
    52В плане

    mysqlnd/pdo password buffer overflow

    ВысокаяCVSS 8,8Proof of conceptEPSS 58 %

    php · php16 июн. 2022 г.

  • CVE-2016-7479
    52В плане

    In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-af

    КритическаяCVSS 9,8Эксплойта нетEPSS 42 %

    php · php11 янв. 2017 г.

  • CVE-2012-2311
    51В плане

    sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle que

    ВысокаяCVSS 7,5Proof of conceptEPSS 69 %

    php · php11 мая 2012 г.

  • CVE-2016-7480
    51В плане

    The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whic

    КритическаяCVSS 9,8Эксплойта нетEPSS 42 %

    php · php11 янв. 2017 г.

  • CVE-2021-32610
    50В плане

    In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

    ВысокаяCVSS 7,1Эксплойта нетEPSS 73 %

    php · archive tar30 июл. 2021 г.

  • CVE-2005-3390
    50В плане

    The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to mod

    ВысокаяCVSS 7,5Proof of conceptEPSS 66 %

    php · php1 нояб. 2005 г.

  • CVE-2016-3074
    50В плане

    Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or

    КритическаяCVSS 9,8Proof of conceptEPSS 37 %

    libgd · libgd26 апр. 2016 г.

  • CVE-2015-6835
    50В плане

    The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, w

    КритическаяCVSS 9,8Proof of conceptEPSS 36 %

    php · php16 мая 2016 г.

  • CVE-2016-3141
    50В плане

    Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a

    КритическаяCVSS 9,8Proof of conceptEPSS 36 %

    php · php31 мар. 2016 г.

  • CVE-2004-0542
    49В плане

    PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arb

    КритическаяCVSS 10,0Эксплойта нетEPSS 31 %

    php · php6 авг. 2004 г.

  • CVE-2018-5712
    48В плане

    An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.

    СредняяCVSS 6,1Эксплойта нетEPSS 80 %

    php · php16 янв. 2018 г.

  • CVE-2016-5385
    47В плане

    PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t

    ВысокаяCVSS 8,1Эксплойта нетEPSS 50 %

    hp · storeever msl6480 tape library firmware18 июл. 2016 г.

  • CVE-2024-1874
    47В плане

    Command injection via array-ish $command parameter of proc_open()

    КритическаяCVSS 9,4Proof of conceptEPSS 33 %

    php · php29 апр. 2024 г.