Записи php
781 опубликованных записей вендора php.
Профиль для исследователя
- Попали в KEV
- 5 · 0,6 %
- С эксплойтом
- 11 · 1,4 %
- Pre-auth RCE
- 165
- С записью об исправлении
- 70 %
- Медиана: публикация → KEV
- 644 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer94
- CWE-20 Improper Input Validation75
- CWE-125 Out-of-bounds Read46
- CWE-189 Numeric Errors32
- CWE-264 Permissions, Privileges, and Access Controls29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
781 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2024-4577Готовый эксплойт | Argument Injection in PHP-CGIphp · php · CWE-78 | Критическая9,8 | KEV | 100,0 % | 9 июн. 2024 г. |
99Срочно | CVE-2019-11043Готовый эксплойт | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Критическая9,8 | KEV | 99,8 % | 28 окт. 2019 г. |
86Срочно | CVE-2020-28949Готовый эксплойт | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | Высокая7,8 | KEV | 84,6 % | 19 нояб. 2020 г. |
81Срочно | CVE-2020-36193Готовый эксплойт | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relatphp · archive tar · CWE-22 | Высокая7,5 | KEV | 70,6 % | 18 янв. 2021 г. |
68На этой неделе | CVE-2015-0235Готовый эксплойт | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Критическая10,0 | — | 94,6 % | 28 янв. 2015 г. |
65На этой неделе | CVE-2018-7584Proof of concept | In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while paphp · php · CWE-119 | Критическая9,8 | — | 87,3 % | 1 мар. 2018 г. |
59В плане | CVE-2018-19518Готовый эксплойт | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of php · php · CWE-88 | Высокая7,5 | — | 96,1 % | 25 нояб. 2018 г. |
56В плане | CVE-2019-6977Proof of concept | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.libgd · libgd · CWE-787 | Высокая8,8 | — | 71,5 % | 26 янв. 2019 г. |
56В плане | CVE-2016-3078Proof of concept | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-bphp · php · CWE-190 | Критическая9,8 | — | 56,1 % | 7 авг. 2016 г. |
54В плане | CVE-2005-1921Готовый эксплойт | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1php · xml rpc · CWE-94 | Высокая7,5 | — | 79,1 % | 5 июл. 2005 г. |
53В плане | CVE-2015-6834Proof of concept | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to executephp · php | Критическая9,8 | — | 46,8 % | 16 мая 2016 г. |
52В плане | CVE-2022-31626Proof of concept | mysqlnd/pdo password buffer overflowphp · php · CWE-120 | Высокая8,8 | — | 58,1 % | 16 июн. 2022 г. |
52В плане | CVE-2016-7479Эксплойта нет | In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-afphp · php · CWE-416 | Критическая9,8 | — | 41,7 % | 11 янв. 2017 г. |
51В плане | CVE-2012-2311Proof of concept | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-89 | Высокая7,5 | — | 69,3 % | 11 мая 2012 г. |
51В плане | CVE-2016-7480Эксплойта нет | The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whicphp · php · CWE-119 | Критическая9,8 | — | 41,6 % | 11 янв. 2017 г. |
50В плане | CVE-2021-32610Эксплойта нет | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.php · archive tar · CWE-59 | Высокая7,1 | — | 73,4 % | 30 июл. 2021 г. |
50В плане | CVE-2005-3390Proof of concept | The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modphp · php | Высокая7,5 | — | 65,5 % | 1 нояб. 2005 г. |
50В плане | CVE-2016-3074Proof of concept | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or libgd · libgd · CWE-681 | Критическая9,8 | — | 37,2 % | 26 апр. 2016 г. |
50В плане | CVE-2015-6835Proof of concept | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, wphp · php | Критическая9,8 | — | 36,2 % | 16 мая 2016 г. |
50В плане | CVE-2016-3141Proof of concept | Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause aphp · php · CWE-119 | Критическая9,8 | — | 36,0 % | 31 мар. 2016 г. |
49В плане | CVE-2004-0542Эксплойта нет | PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbphp · php | Критическая10,0 | — | 31,1 % | 6 авг. 2004 г. |
48В плане | CVE-2018-5712Эксплойта нет | An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.php · php · CWE-79 | Средняя6,1 | — | 79,9 % | 16 янв. 2018 г. |
47В плане | CVE-2016-5385Эксплойта нет | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | Высокая8,1 | — | 50,4 % | 18 июл. 2016 г. |
47В плане | CVE-2024-1874Proof of concept | Command injection via array-ish $command parameter of proc_open()php · php · CWE-116 | Критическая9,4 | — | 32,6 % | 29 апр. 2024 г. |
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2024-457799Срочно
Argument Injection in PHP-CGI
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php9 июн. 2024 г.
- CVE-2019-1104399Срочно
Underflow in PHP-FPM can lead to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php28 окт. 2019 г.
- CVE-2020-2894986Срочно
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 85 %php · archive tar19 нояб. 2020 г.
- CVE-2020-3619381Срочно
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 71 %php · archive tar18 янв. 2021 г.
- CVE-2015-023568На этой неделе
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %gnu · glibc28 янв. 2015 г.
- CVE-2018-758465На этой неделе
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while pa
КритическаяCVSS 9,8Proof of conceptEPSS 87 %php · php1 мар. 2018 г.
- CVE-2018-1951859В плане
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of
ВысокаяCVSS 7,5Готовый эксплойтEPSS 96 %php · php25 нояб. 2018 г.
- CVE-2019-697756В плане
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.
ВысокаяCVSS 8,8Proof of conceptEPSS 71 %libgd · libgd26 янв. 2019 г.
- CVE-2016-307856В плане
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-b
КритическаяCVSS 9,8Proof of conceptEPSS 56 %php · php7 авг. 2016 г.
- CVE-2005-192154В плане
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %php · xml rpc5 июл. 2005 г.
- CVE-2015-683453В плане
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute
КритическаяCVSS 9,8Proof of conceptEPSS 47 %php · php16 мая 2016 г.
- CVE-2022-3162652В плане
mysqlnd/pdo password buffer overflow
ВысокаяCVSS 8,8Proof of conceptEPSS 58 %php · php16 июн. 2022 г.
- CVE-2016-747952В плане
In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-af
КритическаяCVSS 9,8Эксплойта нетEPSS 42 %php · php11 янв. 2017 г.
- CVE-2012-231151В плане
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle que
ВысокаяCVSS 7,5Proof of conceptEPSS 69 %php · php11 мая 2012 г.
- CVE-2016-748051В плане
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whic
КритическаяCVSS 9,8Эксплойта нетEPSS 42 %php · php11 янв. 2017 г.
- CVE-2021-3261050В плане
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
ВысокаяCVSS 7,1Эксплойта нетEPSS 73 %php · archive tar30 июл. 2021 г.
- CVE-2005-339050В плане
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to mod
ВысокаяCVSS 7,5Proof of conceptEPSS 66 %php · php1 нояб. 2005 г.
- CVE-2016-307450В плане
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or
КритическаяCVSS 9,8Proof of conceptEPSS 37 %libgd · libgd26 апр. 2016 г.
- CVE-2015-683550В плане
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, w
КритическаяCVSS 9,8Proof of conceptEPSS 36 %php · php16 мая 2016 г.
- CVE-2016-314150В плане
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a
КритическаяCVSS 9,8Proof of conceptEPSS 36 %php · php31 мар. 2016 г.
- CVE-2004-054249В плане
PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arb
КритическаяCVSS 10,0Эксплойта нетEPSS 31 %php · php6 авг. 2004 г.
- CVE-2018-571248В плане
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.
СредняяCVSS 6,1Эксплойта нетEPSS 80 %php · php16 янв. 2018 г.
- CVE-2016-538547В плане
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
ВысокаяCVSS 8,1Эксплойта нетEPSS 50 %hp · storeever msl6480 tape library firmware18 июл. 2016 г.
- CVE-2024-187447В плане
Command injection via array-ish $command parameter of proc_open()
КритическаяCVSS 9,4Proof of conceptEPSS 33 %php · php29 апр. 2024 г.