Show filters
129 Total Results
Displaying 71-80 of 129
Sort by:
Attacker Value
Unknown
CVE-2009-3292
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
0
Attacker Value
Unknown
CVE-2009-3293
Disclosure Date: September 22, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
0
Attacker Value
Unknown
CVE-2009-2303
Disclosure Date: July 02, 2009 (last updated October 04, 2023)
index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2009-1271
Disclosure Date: April 08, 2009 (last updated October 04, 2023)
The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.
0
Attacker Value
Unknown
CVE-2009-1272
Disclosure Date: April 08, 2009 (last updated October 04, 2023)
The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.
0
Attacker Value
Unknown
CVE-2008-5814
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.
0
Attacker Value
Unknown
CVE-2008-5498
Disclosure Date: December 26, 2008 (last updated October 04, 2023)
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.
0
Attacker Value
Unknown
CVE-2008-5557
Disclosure Date: December 23, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.
0
Attacker Value
Unknown
CVE-2008-5658
Disclosure Date: December 17, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.
0
Attacker Value
Unknown
CVE-2008-5624
Disclosure Date: December 17, 2008 (last updated October 04, 2023)
PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.
0