İçeriğe atla
Noroxi

php kayıtları

php üreticisine ait 781 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
5 · %0,6
Silahlaştırılmış
11 · %1,4
Pre-auth RCE
165
Düzeltme kaydı olan
%70
Yayından KEV’e ortanca
644 gün

Tüm kayıtlar

781 kayıt
  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php11 May 2012

  • Argument Injection in PHP-CGI

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php9 Haz 2024

  • Underflow in PHP-FPM can lead to RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php28 Eki 2019

  • Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %85

    php · archive tar19 Kas 2020

  • Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %71

    php · archive tar18 Oca 2021

  • CVE-2015-0235
    68Bu hafta

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    KritikCVSS 10,0SilahlaştırılmışEPSS %95

    gnu · glibc28 Oca 2015

  • CVE-2018-7584
    65Bu hafta

    In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while pa

    KritikCVSS 9,8Kavram kanıtıEPSS %87

    php · php1 Mar 2018

  • CVE-2018-19518
    59Planlayın

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of

    YüksekCVSS 7,5SilahlaştırılmışEPSS %96

    php · php25 Kas 2018

  • CVE-2019-6977
    56Planlayın

    gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.

    YüksekCVSS 8,8Kavram kanıtıEPSS %71

    libgd · libgd26 Oca 2019

  • CVE-2016-3078
    56Planlayın

    Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-b

    KritikCVSS 9,8Kavram kanıtıEPSS %56

    php · php7 Ağu 2016

  • CVE-2005-1921
    54Planlayın

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1

    YüksekCVSS 7,5SilahlaştırılmışEPSS %79

    php · xml rpc5 Tem 2005

  • CVE-2015-6834
    53Planlayın

    Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute

    KritikCVSS 9,8Kavram kanıtıEPSS %47

    php · php16 May 2016

  • CVE-2022-31626
    52Planlayın

    mysqlnd/pdo password buffer overflow

    YüksekCVSS 8,8Kavram kanıtıEPSS %58

    php · php16 Haz 2022

  • CVE-2016-7479
    52Planlayın

    In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-af

    KritikCVSS 9,8İstismar yokEPSS %42

    php · php11 Oca 2017

  • CVE-2012-2311
    51Planlayın

    sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle que

    YüksekCVSS 7,5Kavram kanıtıEPSS %69

    php · php11 May 2012

  • CVE-2016-7480
    51Planlayın

    The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whic

    KritikCVSS 9,8İstismar yokEPSS %42

    php · php11 Oca 2017

  • CVE-2021-32610
    50Planlayın

    In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

    YüksekCVSS 7,1İstismar yokEPSS %73

    php · archive tar30 Tem 2021

  • CVE-2005-3390
    50Planlayın

    The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to mod

    YüksekCVSS 7,5Kavram kanıtıEPSS %66

    php · php1 Kas 2005

  • CVE-2016-3074
    50Planlayın

    Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or

    KritikCVSS 9,8Kavram kanıtıEPSS %37

    libgd · libgd26 Nis 2016

  • CVE-2015-6835
    50Planlayın

    The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, w

    KritikCVSS 9,8Kavram kanıtıEPSS %36

    php · php16 May 2016

  • CVE-2016-3141
    50Planlayın

    Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a

    KritikCVSS 9,8Kavram kanıtıEPSS %36

    php · php31 Mar 2016

  • CVE-2004-0542
    49Planlayın

    PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arb

    KritikCVSS 10,0İstismar yokEPSS %31

    php · php6 Ağu 2004

  • CVE-2018-5712
    48Planlayın

    An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.

    OrtaCVSS 6,1İstismar yokEPSS %80

    php · php16 Oca 2018

  • CVE-2016-5385
    47Planlayın

    PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t

    YüksekCVSS 8,1İstismar yokEPSS %50

    hp · storeever msl6480 tape library firmware18 Tem 2016

  • CVE-2024-1874
    47Planlayın

    Command injection via array-ish $command parameter of proc_open()

    KritikCVSS 9,4Kavram kanıtıEPSS %33

    php · php29 Nis 2024