Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 883

Количество 3 883

ubuntu логотип

CVE-2011-0754

около 15 лет назад

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2011-0754

около 15 лет назад

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.

CVSS2: 4.4
EPSS: Низкий
debian логотип

CVE-2011-0754

около 15 лет назад

The SplFileInfo::getType function in the Standard PHP Library (SPL) ex ...

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2011-0753

около 15 лет назад

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2011-0753

больше 15 лет назад

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.

EPSS: Низкий
nvd логотип

CVE-2011-0753

около 15 лет назад

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-0753

около 15 лет назад

Race condition in the PCNTL extension in PHP before 5.3.4, when a user ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-0752

около 15 лет назад

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2011-0752

около 15 лет назад

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2011-0752

около 15 лет назад

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-0752

около 15 лет назад

The extract function in PHP before 5.2.15 does not prevent use of the ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-0708

почти 15 лет назад

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2011-0708

почти 15 лет назад

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2011-0708

почти 15 лет назад

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2011-0708

почти 15 лет назад

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms p ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2011-0441

почти 15 лет назад

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

CVSS2: 6.3
EPSS: Низкий
nvd логотип

CVE-2011-0441

почти 15 лет назад

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

CVSS2: 6.3
EPSS: Низкий
debian логотип

CVE-2011-0441

почти 15 лет назад

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows lo ...

CVSS2: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2011-0421

почти 15 лет назад

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2011-0421

около 15 лет назад

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-0754

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.

CVSS2: 4.4
0%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0754

The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.

CVSS2: 4.4
0%
Низкий
около 15 лет назад
debian логотип
CVE-2011-0754

The SplFileInfo::getType function in the Standard PHP Library (SPL) ex ...

CVSS2: 4.4
0%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-0753

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.

CVSS2: 4.3
1%
Низкий
около 15 лет назад
redhat логотип
CVE-2011-0753

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.

1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2011-0753

Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.

CVSS2: 4.3
1%
Низкий
около 15 лет назад
debian логотип
CVE-2011-0753

Race condition in the PCNTL extension in PHP before 5.3.4, when a user ...

CVSS2: 4.3
1%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-0752

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

CVSS2: 5
1%
Низкий
около 15 лет назад
redhat логотип
CVE-2011-0752

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

CVSS2: 2.6
1%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0752

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

CVSS2: 5
1%
Низкий
около 15 лет назад
debian логотип
CVE-2011-0752

The extract function in PHP before 5.2.15 does not prevent use of the ...

CVSS2: 5
1%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-0708

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

CVSS2: 4.3
16%
Средний
почти 15 лет назад
redhat логотип
CVE-2011-0708

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

CVSS2: 2.6
16%
Средний
почти 15 лет назад
nvd логотип
CVE-2011-0708

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) via an image with a crafted Image File Directory (IFD) that triggers a buffer over-read.

CVSS2: 4.3
16%
Средний
почти 15 лет назад
debian логотип
CVE-2011-0708

exif.c in the Exif extension in PHP before 5.3.6 on 64-bit platforms p ...

CVSS2: 4.3
16%
Средний
почти 15 лет назад
ubuntu логотип
CVE-2011-0441

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

CVSS2: 6.3
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-0441

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete arbitrary files via a symlink attack on a directory under /var/lib/php5/.

CVSS2: 6.3
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-0441

The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows lo ...

CVSS2: 6.3
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-0421

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

CVSS2: 4.3
8%
Низкий
почти 15 лет назад
redhat логотип
CVE-2011-0421

The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference) via an empty ZIP archive that is processed with a (1) locateName or (2) statName operation.

CVSS2: 2.6
8%
Низкий
около 15 лет назад

Уязвимостей на страницу