Логотип exploitDog
bind:"CVE-2010-3870" OR bind:"CVE-2010-4645" OR bind:"CVE-2010-3709" OR bind:"CVE-2009-5016"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2010-3870" OR bind:"CVE-2010-4645" OR bind:"CVE-2010-3709" OR bind:"CVE-2009-5016"

Количество 24

Количество 24

nvd логотип

CVE-2009-5016

больше 14 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-5016

больше 14 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-rh65-964j-gj4h

около 3 лет назад

The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.

EPSS: Низкий
github логотип

GHSA-8fg6-84xm-jg65

около 3 лет назад

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2009-5016

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in P ...

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
github логотип
GHSA-rh65-964j-gj4h

The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.

7%
Низкий
около 3 лет назад
github логотип
GHSA-8fg6-84xm-jg65

Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

3%
Низкий
около 3 лет назад

Уязвимостей на страницу