Show filters
118 Total Results
Displaying 71-80 of 118
Sort by:
Attacker Value
Unknown

CVE-2007-1717

Disclosure Date: March 28, 2007 (last updated October 04, 2023)
The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. NOTE: this issue might be security-relevant in cases when the trailing contents of e-mail messages are important, such as logging information or if the message is expected to be well-formed.
0
Attacker Value
Unknown

CVE-2007-1718

Disclosure Date: March 28, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of the (1) Subject or (2) To parameter, as demonstrated by a parameter containing a "\r\n\t\n" sequence, related to an increment bug in the SKIP_LONG_HEADER_SEP macro.
0
Attacker Value
Unknown

CVE-2007-1700

Disclosure Date: March 27, 2007 (last updated October 04, 2023)
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.
0
Attacker Value
Unknown

CVE-2007-1583

Disclosure Date: March 21, 2007 (last updated October 04, 2023)
The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.
0
Attacker Value
Unknown

CVE-2007-1582

Disclosure Date: March 21, 2007 (last updated October 04, 2023)
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error handler, which can be used to destroy and modify internal resources.
0
Attacker Value
Unknown

CVE-2007-1461

Disclosure Date: March 14, 2007 (last updated October 04, 2023)
The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.
0
Attacker Value
Unknown

CVE-2007-1460

Disclosure Date: March 14, 2007 (last updated October 04, 2023)
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.
0
Attacker Value
Unknown

CVE-2007-1378

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.
0
Attacker Value
Unknown

CVE-2007-1376

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.
0
Attacker Value
Unknown

CVE-2007-1379

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.
0