Show filters
117 Total Results
Displaying 61-70 of 117
Sort by:
Attacker Value
Unknown

CVE-2008-2050

Disclosure Date: May 05, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the FastCGI SAPI (fastcgi.c) in PHP before 5.2.6 has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2008-2051

Disclosure Date: May 05, 2008 (last updated October 04, 2023)
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
0
Attacker Value
Unknown

CVE-2007-4658

Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.
0
Attacker Value
Unknown

CVE-2007-4652

Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.
0
Attacker Value
Unknown

CVE-2007-3799

Disclosure Date: July 16, 2007 (last updated October 04, 2023)
The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.
0
Attacker Value
Unknown

CVE-2007-2872

Disclosure Date: June 04, 2007 (last updated October 04, 2023)
Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.
0
Attacker Value
Unknown

CVE-2007-2844

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
PHP 4.x and 5.x before 5.2.1, when running on multi-threaded systems, does not ensure thread safety for libc crypt function calls using protection schemes such as a mutex, which creates race conditions that allow remote attackers to overwrite internal program memory and gain system access.
0
Attacker Value
Unknown

CVE-2006-7205

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value.
0
Attacker Value
Unknown

CVE-2007-2510

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.
0
Attacker Value
Unknown

CVE-2007-2509

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.
0