Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

debian логотип

CVE-2010-1129

около 16 лет назад

The safe_mode implementation in PHP before 5.2.13 does not properly ha ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-1128

около 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2010-1128

около 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2010-1128

около 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2010-1128

около 16 лет назад

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2010-0397

около 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2010-0397

около 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-0397

около 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-0397

около 16 лет назад

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing m ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-5016

больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2009-5016

больше 16 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-5016

больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-5016

больше 15 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2009-4418

больше 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-4418

больше 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

EPSS: Низкий
nvd логотип

CVE-2009-4418

больше 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-4418

больше 16 лет назад

The unserialize function in PHP 5.3.0 and earlier allows context-depen ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-4143

больше 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2009-4143

больше 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

EPSS: Низкий
nvd логотип

CVE-2009-4143

больше 16 лет назад

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2010-1129

The safe_mode implementation in PHP before 5.2.13 does not properly ha ...

CVSS2: 7.5
2%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
5%
Низкий
около 16 лет назад
redhat логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 2.6
5%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

CVSS2: 6.4
5%
Низкий
около 16 лет назад
debian логотип
CVE-2010-1128

The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not ...

CVSS2: 6.4
5%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
8%
Низкий
около 16 лет назад
redhat логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 4.3
8%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

CVSS2: 5
8%
Низкий
около 16 лет назад
debian логотип
CVE-2010-0397

The xmlrpc extension in PHP 5.3.1 does not properly handle a missing m ...

CVSS2: 5
8%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
redhat логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 4.3
3%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
0%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences.

CVSS2: 5
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-4418

The unserialize function in PHP 5.3.0 and earlier allows context-depen ...

CVSS2: 5
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
8%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

8%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-4143

PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

CVSS2: 10
8%
Низкий
больше 16 лет назад

Уязвимостей на страницу