Show filters
66 Total Results
Displaying 41-50 of 66
Sort by:
Attacker Value
Unknown
CVE-2010-3710
Disclosure Date: October 25, 2010 (last updated October 04, 2023)
Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string.
0
Attacker Value
Unknown
CVE-2010-2484
Disclosure Date: August 20, 2010 (last updated October 04, 2023)
The strrchr function in PHP 5.2 before 5.2.14 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.
0
Attacker Value
Unknown
CVE-2010-3065
Disclosure Date: August 20, 2010 (last updated October 04, 2023)
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
0
Attacker Value
Unknown
CVE-2010-2225
Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.
0
Attacker Value
Unknown
CVE-2010-2190
Disclosure Date: June 08, 2010 (last updated October 04, 2023)
The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
0
Attacker Value
Unknown
CVE-2010-2191
Disclosure Date: June 08, 2010 (last updated October 04, 2023)
The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler. NOTE: vectors 2 through 4 are related to the call time pass by reference feature.
0
Attacker Value
Unknown
CVE-2010-2101
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
0
Attacker Value
Unknown
CVE-2010-2100
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) http_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
0
Attacker Value
Unknown
CVE-2010-2093
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction occurs.
0
Attacker Value
Unknown
CVE-2010-2097
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
0