php kayıtları
php üreticisine ait 781 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 5 · %0,6
- Silahlaştırılmış
- 11 · %1,4
- Pre-auth RCE
- 165
- Düzeltme kaydı olan
- %70
- Yayından KEV’e ortanca
- 644 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer94
- CWE-20 Improper Input Validation75
- CWE-125 Out-of-bounds Read46
- CWE-189 Numeric Errors32
- CWE-264 Permissions, Privileges, and Access Controls29
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
781 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2012-1823Silahlaştırılmış | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Kritik9,8 | KEV | %100,0 | 11 May 2012 |
99Hemen | CVE-2024-4577Silahlaştırılmış | Argument Injection in PHP-CGIphp · php · CWE-78 | Kritik9,8 | KEV | %100,0 | 9 Haz 2024 |
99Hemen | CVE-2019-11043Silahlaştırılmış | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Kritik9,8 | KEV | %99,8 | 28 Eki 2019 |
86Hemen | CVE-2020-28949Silahlaştırılmış | Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as filphp · archive tar | Yüksek7,8 | KEV | %84,6 | 19 Kas 2020 |
81Hemen | CVE-2020-36193Silahlaştırılmış | Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relatphp · archive tar · CWE-22 | Yüksek7,5 | KEV | %70,6 | 18 Oca 2021 |
68Bu hafta | CVE-2015-0235Silahlaştırılmış | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Kritik10,0 | — | %94,6 | 28 Oca 2015 |
65Bu hafta | CVE-2018-7584Kavram kanıtı | In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while paphp · php · CWE-119 | Kritik9,8 | — | %87,3 | 1 Mar 2018 |
59Planlayın | CVE-2018-19518Silahlaştırılmış | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of php · php · CWE-88 | Yüksek7,5 | — | %96,1 | 25 Kas 2018 |
56Planlayın | CVE-2019-6977Kavram kanıtı | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.libgd · libgd · CWE-787 | Yüksek8,8 | — | %71,5 | 26 Oca 2019 |
56Planlayın | CVE-2016-3078Kavram kanıtı | Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-bphp · php · CWE-190 | Kritik9,8 | — | %56,1 | 7 Ağu 2016 |
54Planlayın | CVE-2005-1921Silahlaştırılmış | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1php · xml rpc · CWE-94 | Yüksek7,5 | — | %79,1 | 5 Tem 2005 |
53Planlayın | CVE-2015-6834Kavram kanıtı | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to executephp · php | Kritik9,8 | — | %46,8 | 16 May 2016 |
52Planlayın | CVE-2022-31626Kavram kanıtı | mysqlnd/pdo password buffer overflowphp · php · CWE-120 | Yüksek8,8 | — | %58,1 | 16 Haz 2022 |
52Planlayın | CVE-2016-7479İstismar yok | In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-afphp · php · CWE-416 | Kritik9,8 | — | %41,7 | 11 Oca 2017 |
51Planlayın | CVE-2012-2311Kavram kanıtı | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-89 | Yüksek7,5 | — | %69,3 | 11 May 2012 |
51Planlayın | CVE-2016-7480İstismar yok | The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whicphp · php · CWE-119 | Kritik9,8 | — | %41,6 | 11 Oca 2017 |
50Planlayın | CVE-2021-32610İstismar yok | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.php · archive tar · CWE-59 | Yüksek7,1 | — | %73,4 | 30 Tem 2021 |
50Planlayın | CVE-2005-3390Kavram kanıtı | The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modphp · php | Yüksek7,5 | — | %65,5 | 1 Kas 2005 |
50Planlayın | CVE-2016-3074Kavram kanıtı | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or libgd · libgd · CWE-681 | Kritik9,8 | — | %37,2 | 26 Nis 2016 |
50Planlayın | CVE-2015-6835Kavram kanıtı | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, wphp · php | Kritik9,8 | — | %36,2 | 16 May 2016 |
50Planlayın | CVE-2016-3141Kavram kanıtı | Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause aphp · php · CWE-119 | Kritik9,8 | — | %36,0 | 31 Mar 2016 |
49Planlayın | CVE-2004-0542İstismar yok | PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbphp · php | Kritik10,0 | — | %31,1 | 6 Ağu 2004 |
48Planlayın | CVE-2018-5712İstismar yok | An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.php · php · CWE-79 | Orta6,1 | — | %79,9 | 16 Oca 2018 |
47Planlayın | CVE-2016-5385İstismar yok | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from thp · storeever msl6480 tape library firmware · CWE-601 | Yüksek8,1 | — | %50,4 | 18 Tem 2016 |
47Planlayın | CVE-2024-1874Kavram kanıtı | Command injection via array-ish $command parameter of proc_open()php · php · CWE-116 | Kritik9,4 | — | %32,6 | 29 Nis 2024 |
- CVE-2012-182399Hemen
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php11 May 2012
- CVE-2024-457799Hemen
Argument Injection in PHP-CGI
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php9 Haz 2024
- CVE-2019-1104399Hemen
Underflow in PHP-FPM can lead to RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100php · php28 Eki 2019
- CVE-2020-2894986Hemen
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %85php · archive tar19 Kas 2020
- CVE-2020-3619381Hemen
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a relat
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %71php · archive tar18 Oca 2021
- CVE-2015-023568Bu hafta
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
KritikCVSS 10,0SilahlaştırılmışEPSS %95gnu · glibc28 Oca 2015
- CVE-2018-758465Bu hafta
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while pa
KritikCVSS 9,8Kavram kanıtıEPSS %87php · php1 Mar 2018
- CVE-2018-1951859Planlayın
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of
YüksekCVSS 7,5SilahlaştırılmışEPSS %96php · php25 Kas 2018
- CVE-2019-697756Planlayın
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.
YüksekCVSS 8,8Kavram kanıtıEPSS %71libgd · libgd26 Oca 2019
- CVE-2016-307856Planlayın
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-b
KritikCVSS 9,8Kavram kanıtıEPSS %56php · php7 Ağu 2016
- CVE-2005-192154Planlayın
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1
YüksekCVSS 7,5SilahlaştırılmışEPSS %79php · xml rpc5 Tem 2005
- CVE-2015-683453Planlayın
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute
KritikCVSS 9,8Kavram kanıtıEPSS %47php · php16 May 2016
- CVE-2022-3162652Planlayın
mysqlnd/pdo password buffer overflow
YüksekCVSS 8,8Kavram kanıtıEPSS %58php · php16 Haz 2022
- CVE-2016-747952Planlayın
In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-af
KritikCVSS 9,8İstismar yokEPSS %42php · php11 Oca 2017
- CVE-2012-231151Planlayın
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle que
YüksekCVSS 7,5Kavram kanıtıEPSS %69php · php11 May 2012
- CVE-2016-748051Planlayın
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, whic
KritikCVSS 9,8İstismar yokEPSS %42php · php11 Oca 2017
- CVE-2021-3261050Planlayın
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
YüksekCVSS 7,1İstismar yokEPSS %73php · archive tar30 Tem 2021
- CVE-2005-339050Planlayın
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to mod
YüksekCVSS 7,5Kavram kanıtıEPSS %66php · php1 Kas 2005
- CVE-2016-307450Planlayın
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or
KritikCVSS 9,8Kavram kanıtıEPSS %37libgd · libgd26 Nis 2016
- CVE-2015-683550Planlayın
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, w
KritikCVSS 9,8Kavram kanıtıEPSS %36php · php16 May 2016
- CVE-2016-314150Planlayın
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a
KritikCVSS 9,8Kavram kanıtıEPSS %36php · php31 Mar 2016
- CVE-2004-054249Planlayın
PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arb
KritikCVSS 10,0İstismar yokEPSS %31php · php6 Ağu 2004
- CVE-2018-571248Planlayın
An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1.
OrtaCVSS 6,1İstismar yokEPSS %80php · php16 Oca 2018
- CVE-2016-538547Planlayın
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from t
YüksekCVSS 8,1İstismar yokEPSS %50hp · storeever msl6480 tape library firmware18 Tem 2016
- CVE-2024-187447Planlayın
Command injection via array-ish $command parameter of proc_open()
KritikCVSS 9,4Kavram kanıtıEPSS %33php · php29 Nis 2024