Show filters
89 Total Results
Displaying 81-89 of 89
Sort by:
Attacker Value
Unknown
CVE-2008-3658
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
0
Attacker Value
Unknown
CVE-2008-3660
Disclosure Date: August 15, 2008 (last updated October 04, 2023)
PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.
0
Attacker Value
Unknown
CVE-2008-2666
Disclosure Date: June 20, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier allow context-dependent attackers to bypass safe_mode restrictions by creating a subdirectory named http: and then placing ../ (dot dot slash) sequences in an http URL argument to the (1) chdir or (2) ftok function.
0
Attacker Value
Unknown
CVE-2008-2107
Disclosure Date: May 07, 2008 (last updated October 04, 2023)
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 32-bit systems, performs a multiplication using values that can produce a zero seed in rare circumstances, which allows context-dependent attackers to predict subsequent values of the rand and mt_rand functions and possibly bypass protection mechanisms that rely on an unknown initial seed.
0
Attacker Value
Unknown
CVE-2008-2050
Disclosure Date: May 05, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the FastCGI SAPI (fastcgi.c) in PHP before 5.2.6 has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2008-2051
Disclosure Date: May 05, 2008 (last updated October 04, 2023)
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
0
Attacker Value
Unknown
CVE-2007-4850
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.
0
Attacker Value
Unknown
CVE-2007-5447
Disclosure Date: October 14, 2007 (last updated October 04, 2023)
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function.
0
Attacker Value
Unknown
CVE-2007-1581
Disclosure Date: March 21, 2007 (last updated October 04, 2023)
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify internal resources. NOTE: it was later reported that PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 are also affected.
0