Show filters
71 Total Results
Displaying 51-60 of 71
Sort by:
Attacker Value
Unknown

CVE-2007-3799

Disclosure Date: July 16, 2007 (last updated October 04, 2023)
The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.
0
Attacker Value
Unknown

CVE-2007-2844

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
PHP 4.x and 5.x before 5.2.1, when running on multi-threaded systems, does not ensure thread safety for libc crypt function calls using protection schemes such as a mutex, which creates race conditions that allow remote attackers to overwrite internal program memory and gain system access.
0
Attacker Value
Unknown

CVE-2007-2510

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.
0
Attacker Value
Unknown

CVE-2007-2509

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
0
Attacker Value
Unknown

CVE-2007-2511

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.
0
Attacker Value
Unknown

CVE-2007-1885

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the str_replace function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via a single character search string in conjunction with a long replacement string, which overflows a 32 bit length counter. NOTE: this is probably the same issue as CVE-2007-0906.6.
0
Attacker Value
Unknown

CVE-2007-1883

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convert_to_* functions with its input parameters.
0
Attacker Value
Unknown

CVE-2007-1888

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Buffer overflow in the sqlite_decode_binary function in src/encode.c in SQLite 2, as used by PHP 4.x through 5.x and other applications, allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter. NOTE: some PHP installations use a bundled version of sqlite without this vulnerability. The SQLite developer has argued that this issue could be due to a misuse of the sqlite_decode_binary() API.
0
Attacker Value
Unknown

CVE-2007-1886

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the str_replace function in PHP 4.4.5 and PHP 5.2.1 allows context-dependent attackers to have an unknown impact via a single character search string in conjunction with a single character replacement string, which causes an "off by one overflow."
0
Attacker Value
Unknown

CVE-2007-1001

Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.
0