Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

ubuntu логотип

CVE-2009-2687

больше 16 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2009-2687

почти 17 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2009-2687

больше 16 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2009-2687

больше 16 лет назад

The exif_read_data function in the Exif module in PHP before 5.2.10 al ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2009-2626

больше 16 лет назад

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2009-2626

больше 16 лет назад

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2009-2626

больше 16 лет назад

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2 ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2009-1272

почти 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-1272

около 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1272

почти 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-1272

почти 17 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x befo ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1271

почти 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2009-1271

больше 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2009-1271

почти 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2009-1271

почти 17 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2008-7068

больше 16 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2008-7068

больше 17 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

EPSS: Низкий
nvd логотип

CVE-2008-7068

больше 16 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2008-7068

больше 16 лет назад

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2008-7002

больше 16 лет назад

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
12%
Средний
больше 16 лет назад
redhat логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 5.8
12%
Средний
почти 17 лет назад
nvd логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

CVSS2: 4.3
12%
Средний
больше 16 лет назад
debian логотип
CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 al ...

CVSS2: 4.3
12%
Средний
больше 16 лет назад
ubuntu логотип
CVE-2009-2626

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.

CVSS2: 6.4
8%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2626

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable.

CVSS2: 6.4
8%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2626

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2 ...

CVSS2: 6.4
8%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
2%
Низкий
почти 17 лет назад
redhat логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
2%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x befo ...

CVSS2: 5
2%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
10%
Средний
почти 17 лет назад
redhat логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 4.3
10%
Средний
больше 17 лет назад
nvd логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
10%
Средний
почти 17 лет назад
debian логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before ...

CVSS2: 5
10%
Средний
почти 17 лет назад
ubuntu логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
0%
Низкий
больше 16 лет назад
redhat логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can modify or add database entries but does not have permissions to truncate the file.

CVSS2: 6.4
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-7068

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent ...

CVSS2: 6.4
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-7002

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

CVSS2: 7.2
0%
Низкий
больше 16 лет назад

Уязвимостей на страницу