Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown
CVE-2012-0057
Disclosure Date: February 02, 2012 (last updated October 04, 2023)
PHP before 5.3.9 has improper libxslt security settings, which allows remote attackers to create arbitrary files via a crafted XSLT stylesheet that uses the libxslt output extension.
0
Attacker Value
Unknown
CVE-2011-4885
Disclosure Date: December 30, 2011 (last updated October 04, 2023)
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
0
Attacker Value
Unknown
CVE-2011-3268
Disclosure Date: August 25, 2011 (last updated October 04, 2023)
Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.
0
Attacker Value
Unknown
CVE-2011-3267
Disclosure Date: August 25, 2011 (last updated October 04, 2023)
PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-3182
Disclosure Date: August 25, 2011 (last updated October 04, 2023)
PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffer overflow by leveraging the ability to provide an arbitrary value for a function argument, related to (1) ext/curl/interface.c, (2) ext/date/lib/parse_date.c, (3) ext/date/lib/parse_iso_intervals.c, (4) ext/date/lib/parse_tz.c, (5) ext/date/lib/timelib.c, (6) ext/pdo_odbc/pdo_odbc.c, (7) ext/reflection/php_reflection.c, (8) ext/soap/php_sdl.c, (9) ext/xmlrpc/libxmlrpc/base64.c, (10) TSRM/tsrm_win32.c, and (11) the strtotime function.
0
Attacker Value
Unknown
CVE-2011-2202
Disclosure Date: June 16, 2011 (last updated October 04, 2023)
The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, via a crafted upload request, related to a "file path injection vulnerability."
0
Attacker Value
Unknown
CVE-2011-1938
Disclosure Date: May 31, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.
0
Attacker Value
Unknown
CVE-2011-0441
Disclosure Date: March 29, 2011 (last updated October 04, 2023)
The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.
0
Attacker Value
Unknown
CVE-2011-1148
Disclosure Date: March 18, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in the substr_replace function in PHP 5.3.6 and earlier allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by using the same variable for multiple arguments.
0
Attacker Value
Unknown
CVE-2011-0420
Disclosure Date: February 19, 2011 (last updated October 04, 2023)
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial of service (crash) via an invalid size argument, which triggers a NULL pointer dereference.
0