Software
php
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
60
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-1999-0238 | 10.0 | HIGH | php.cgi allows attackers to read any file on the system. |
| CVE-2000-0059 | 10.0 | HIGH | PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execut... |
| CVE-2000-0967 | 10.0 | HIGH | PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that... |
| CVE-2003-0861 | 10.0 | HIGH | Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors. |
| CVE-2003-0860 | 10.0 | HIGH | Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors. |
| CVE-2004-0542 | 10.0 | HIGH | PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwri... |
| CVE-2004-1018 | 10.0 | HIGH | Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via... |
| CVE-2004-1019 | 10.0 | HIGH | The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrus... |
| CVE-2004-1063 | 10.0 | HIGH | PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restriction... |
| CVE-2004-1064 | 10.0 | HIGH | The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attacke... |
| CVE-2004-1065 | 10.0 | HIGH | Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section... |
| CVE-2007-0448 | 10.0 | HIGH | The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and rea... |
| CVE-2006-4812 | 10.0 | HIGH | Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with... |
| CVE-2007-0910 | 10.0 | HIGH | Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors. |
| CVE-2006-4485 | 10.0 | HIGH | The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read. |
| CVE-2008-5557 | 10.0 | HIGH | Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent atta... |
| CVE-2008-2050 | 10.0 | HIGH | Stack-based buffer overflow in the FastCGI SAPI (fastcgi.c) in PHP before 5.2.6 has unknown impact and attack vectors. |
| CVE-2008-2051 | 10.0 | HIGH | The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars." |
| CVE-2009-4143 | 10.0 | HIGH | PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION supe... |
| CVE-2011-3268 | 10.0 | HIGH | Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different... |
| CVE-2012-2376 | 10.0 | HIGH | Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via crafted arguments t... |
| CVE-2012-2688 | 10.0 | HIGH | Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and re... |
| CVE-2015-0235 | 10.0 | HIGH | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to ex... |
| CVE-2007-1399 | 9.8 | N/A | Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arb... |
| CVE-2007-1383 | 9.8 | N/A | Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, whi... |
| CVE-2010-1866 | 9.8 | N/A | The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (cra... |
| CVE-2008-0599 | 9.8 | N/A | The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRA... |
| CVE-2008-2108 | 9.8 | N/A | The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero... |
| CVE-2011-1939 | 9.8 | N/A | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql i... |
| CVE-2012-1823 | 9.8 | N/A | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack... |
| CVE-2014-3622 | 9.8 | N/A | Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitra... |
| CVE-2014-9912 | 9.8 | N/A | The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly... |
| CVE-2015-4116 | 9.8 | N/A | Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to e... |
| CVE-2015-6835 | 9.8 | N/A | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote at... |
| CVE-2015-6834 | 9.8 | N/A | Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via... |
| CVE-2015-5589 | 9.8 | N/A | The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer... |
| CVE-2015-4643 | 9.8 | N/A | Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to ex... |
| CVE-2015-4642 | 9.8 | N/A | The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to exec... |
| CVE-2015-4603 | 9.8 | N/A | The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to... |
| CVE-2015-4602 | 9.8 | N/A | The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers... |