Show filters
69 Total Results
Displaying 21-30 of 69
Sort by:
Attacker Value
Unknown
CVE-2012-0057
Disclosure Date: February 02, 2012 (last updated October 04, 2023)
PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.
0
Attacker Value
Unknown
CVE-2011-4885
Disclosure Date: December 30, 2011 (last updated October 04, 2023)
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
0
Attacker Value
Unknown
CVE-2011-3268
Disclosure Date: August 25, 2011 (last updated October 04, 2023)
Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.
0
Attacker Value
Unknown
CVE-2011-3267
Disclosure Date: August 25, 2011 (last updated October 04, 2023)
PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-3182
Disclosure Date: August 25, 2011 (last updated October 04, 2023)
PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffer overflow by leveraging the ability to provide an arbitrary value for a function argument, related to (1) ext/curl/interface.c, (2) ext/date/lib/parse_date.c, (3) ext/date/lib/parse_iso_intervals.c, (4) ext/date/lib/parse_tz.c, (5) ext/date/lib/timelib.c, (6) ext/pdo_odbc/pdo_odbc.c, (7) ext/reflection/php_reflection.c, (8) ext/soap/php_sdl.c, (9) ext/xmlrpc/libxmlrpc/base64.c, (10) TSRM/tsrm_win32.c, and (11) the strtotime function.
0
Attacker Value
Unknown
CVE-2011-2202
Disclosure Date: June 16, 2011 (last updated October 04, 2023)
The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."
0
Attacker Value
Unknown
CVE-2011-1470
Disclosure Date: March 20, 2011 (last updated October 04, 2023)
The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a ziparchive stream that is not properly handled by the stream_get_contents function.
0
Attacker Value
Unknown
CVE-2011-0421
Disclosure Date: March 20, 2011 (last updated October 04, 2023)
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.
0
Attacker Value
Unknown
CVE-2011-1466
Disclosure Date: March 20, 2011 (last updated October 04, 2023)
Integer overflow in the SdnToJulian function in the Calendar extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via a large integer in the first argument to the cal_from_jd function.
0
Attacker Value
Unknown
CVE-2011-1467
Disclosure Date: March 20, 2011 (last updated October 04, 2023)
Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a related issue to CVE-2010-4409.
0