Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 866

Количество 3 866

redhat логотип

CVE-2011-4153

больше 13 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4153

больше 13 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4153

больше 13 лет назад

PHP 5.3.8 does not always check the return value of the zend_strndup f ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3379

почти 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2011-3379

почти 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2011-3379

почти 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2011-3379

почти 14 лет назад

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __auto ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-3336

больше 5 лет назад

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2011-3336

больше 5 лет назад

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2011-3268

около 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2011-3268

около 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2011-3268

около 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-3268

около 14 лет назад

Buffer overflow in the crypt function in PHP before 5.3.7 allows conte ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-3267

около 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2011-3267

около 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2011-3267

около 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-3267

около 14 лет назад

PHP before 5.3.7 does not properly implement the error_log function, w ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3189

около 14 лет назад

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2011-3189

около 14 лет назад

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-3189

около 14 лет назад

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 4.3
5%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.

CVSS2: 5
5%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4153

PHP 5.3.8 does not always check the return value of the zend_strndup f ...

CVSS2: 5
5%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 5.1
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2011-3379

The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __auto ...

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-3336

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

CVSS3: 7.5
24%
Средний
больше 5 лет назад
nvd логотип
CVE-2011-3336

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

CVSS3: 7.5
24%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
9%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 1.9
9%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.

CVSS2: 10
9%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3268

Buffer overflow in the crypt function in PHP before 5.3.7 allows conte ...

CVSS2: 10
9%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
4%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 1.9
4%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 5
4%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3267

PHP before 5.3.7 does not properly implement the error_log function, w ...

CVSS2: 5
4%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3189

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4.3
1%
Низкий
около 14 лет назад
redhat логотип
CVE-2011-3189

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3189

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

CVSS2: 4.3
1%
Низкий
около 14 лет назад

Уязвимостей на страницу