Show filters
103 Total Results
Displaying 41-50 of 103
Sort by:
Attacker Value
Unknown
CVE-2009-3293
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
0
Attacker Value
Unknown
CVE-2008-7068
Disclosure Date: August 25, 2009 (last updated October 04, 2023)
The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.
0
Attacker Value
Unknown
CVE-2008-5814
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.
0
Attacker Value
Unknown
CVE-2008-5557
Disclosure Date: December 23, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.
0
Attacker Value
Unknown
CVE-2008-4107
Disclosure Date: September 18, 2008 (last updated October 04, 2023)
The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-relevant functionality, as demonstrated by the password-reset functionality in Joomla! 1.5.x and WordPress before 2.6.2, a different vulnerability than CVE-2008-2107, CVE-2008-2108, and CVE-2008-4102.
0
Attacker Value
Unknown
CVE-2008-3659
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to the explode function. NOTE: the scope of this issue is limited since most applications would not use an attacker-controlled delimiter, but local attacks against safe_mode are feasible.
0
Attacker Value
Unknown
CVE-2008-3658
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2008-3660
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.
0
Attacker Value
Unknown
CVE-2007-4658
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.
0
Attacker Value
Unknown
CVE-2007-4652
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.
0