Show filters
117 Total Results
Displaying 111-117 of 117
Sort by:
Attacker Value
Unknown

CVE-2004-0595

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
0
Attacker Value
Unknown

CVE-2003-1303

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.
0
Attacker Value
Unknown

CVE-2003-0860

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.
0
Attacker Value
Unknown

CVE-2003-0863

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.
0
Attacker Value
Unknown

CVE-2003-0861

Disclosure Date: November 17, 2003 (last updated February 22, 2025)
Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.
0
Attacker Value
Unknown

CVE-2003-0166

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.
0
Attacker Value
Unknown

CVE-2003-0172

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.
0