Show filters
65 Total Results
Displaying 61-65 of 65
Sort by:
Attacker Value
Unknown
CVE-2014-3478
Disclosure Date: July 09, 2014 (last updated October 05, 2023)
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
0
Attacker Value
Unknown
CVE-2013-7328
Disclosure Date: February 18, 2014 (last updated October 05, 2023)
Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service (application crash) or obtain sensitive information via an imagecrop function call with a negative value for the (1) x or (2) y dimension, a different vulnerability than CVE-2013-7226.
0
Attacker Value
Unknown
CVE-2014-2020
Disclosure Date: February 18, 2014 (last updated October 05, 2023)
ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.
0
Attacker Value
Unknown
CVE-2013-7226
Disclosure Date: February 18, 2014 (last updated October 05, 2023)
Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an imagecrop function call with a large x dimension value, leading to a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2013-7327
Disclosure Date: February 18, 2014 (last updated October 05, 2023)
The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments that lead to use of a NULL pointer as a return value, a different vulnerability than CVE-2013-7226.
0