Show filters
93 Total Results
Displaying 81-90 of 93
Sort by:
Attacker Value
Unknown
CVE-2008-2050
Disclosure Date: May 05, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the FastCGI SAPI (fastcgi.c) in PHP before 5.2.6 has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2008-2051
Disclosure Date: May 05, 2008 (last updated October 04, 2023)
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
0
Attacker Value
Unknown
CVE-2007-4658
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.
0
Attacker Value
Unknown
CVE-2007-4661
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting in a heap-based buffer overflow. NOTE: this is due to an incomplete fix for CVE-2007-2872.
0
Attacker Value
Unknown
CVE-2007-4507
Disclosure Date: August 23, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrary code via long arguments to the (1) ntuser_getuserlist, (2) ntuser_getuserinfo, (3) ntuser_getusergroups, or (4) ntuser_getdomaincontroller functions.
0
Attacker Value
Unknown
CVE-2007-4255
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function.
0
Attacker Value
Unknown
CVE-2007-4033
Disclosure Date: July 27, 2007 (last updated October 04, 2023)
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.
0
Attacker Value
Unknown
CVE-2007-4010
Disclosure Date: July 26, 2007 (last updated October 04, 2023)
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.
0
Attacker Value
Unknown
CVE-2007-3806
Disclosure Date: July 17, 2007 (last updated October 04, 2023)
The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure.
0
Attacker Value
Unknown
CVE-2007-3799
Disclosure Date: July 16, 2007 (last updated October 04, 2023)
The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from (1) PATH_INFO, (2) the session_id function, and (3) the session_start function, which are not encoded or filtered when the new session cookie is generated, a related issue to CVE-2006-0207.
0