Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 000

Количество 4 000

redhat логотип

CVE-2010-3436

почти 16 лет назад

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.

EPSS: Низкий
nvd логотип

CVE-2010-3436

больше 15 лет назад

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3436

больше 15 лет назад

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attacke ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-3065

почти 16 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2010-3065

около 16 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-3065

почти 16 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3065

почти 16 лет назад

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 throu ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-3064

почти 16 лет назад

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2010-3064

около 16 лет назад

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2010-3064

почти 16 лет назад

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-3064

почти 16 лет назад

Stack-based buffer overflow in the php_mysqlnd_auth_write function in ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2010-3063

почти 16 лет назад

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2010-3063

около 16 лет назад

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2010-3063

почти 16 лет назад

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3063

почти 16 лет назад

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-3062

почти 16 лет назад

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2010-3062

около 16 лет назад

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2010-3062

почти 16 лет назад

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3062

почти 16 лет назад

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-2950

почти 16 лет назад

Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the phar_stream_flush function, leading to errors in the php_stream_wrapper_log_error function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2010-3436

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.

6%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-3436

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.

CVSS2: 5
6%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3436

fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attacke ...

CVSS2: 5
6%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-3065

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

CVSS2: 5
2%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-3065

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-3065

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

CVSS2: 5
2%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-3065

The default session serializer in PHP 5.2 through 5.2.13 and 5.3 throu ...

CVSS2: 5
2%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-3064

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

CVSS2: 6.8
2%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-3064

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

CVSS2: 5.1
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-3064

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

CVSS2: 6.8
2%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-3064

Stack-based buffer overflow in the php_mysqlnd_auth_write function in ...

CVSS2: 6.8
2%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-3063

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

CVSS2: 5
2%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-3063

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

CVSS2: 5.1
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-3063

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

CVSS2: 5
2%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-3063

The php_mysqlnd_read_error_from_line function in the Mysqlnd extension ...

CVSS2: 5
2%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-3062

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

CVSS2: 5
3%
Низкий
почти 16 лет назад
redhat логотип
CVE-2010-3062

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

CVSS2: 2.6
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-3062

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

CVSS2: 5
3%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-3062

mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3 ...

CVSS2: 5
3%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-2950

Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the phar_stream_flush function, leading to errors in the php_stream_wrapper_log_error function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.

CVSS2: 6.8
6%
Низкий
почти 16 лет назад

Уязвимостей на страницу