Show filters
116 Total Results
Displaying 101-110 of 116
Sort by:
Attacker Value
Unknown

CVE-2005-3319

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.
0
Attacker Value
Unknown

CVE-2004-1019

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
0
Attacker Value
Unknown

CVE-2004-1065

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
0
Attacker Value
Unknown

CVE-2004-1392

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
0
Attacker Value
Unknown

CVE-2004-0595

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
0
Attacker Value
Unknown

CVE-2003-0860

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.
0
Attacker Value
Unknown

CVE-2003-0861

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.
0
Attacker Value
Unknown

CVE-2003-0166

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.
0
Attacker Value
Unknown

CVE-2002-2309

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
0
Attacker Value
Unknown

CVE-2002-2215

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822_write_address function.
0