Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 000

Количество 4 000

redhat логотип

CVE-2009-3559

почти 17 лет назад

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

EPSS: Низкий
nvd логотип

CVE-2009-3559

больше 16 лет назад

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3559

больше 16 лет назад

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recogn ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-3558

больше 16 лет назад

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2009-3558

почти 17 лет назад

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

EPSS: Низкий
nvd логотип

CVE-2009-3558

больше 16 лет назад

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-3558

больше 16 лет назад

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 an ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2009-3557

больше 16 лет назад

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-3557

почти 17 лет назад

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

EPSS: Низкий
nvd логотип

CVE-2009-3557

больше 16 лет назад

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-3557

больше 16 лет назад

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-3294

почти 17 лет назад

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-3294

почти 17 лет назад

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-3294

почти 17 лет назад

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5 ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3293

почти 17 лет назад

Unspecified vulnerability in the imagecolortransparent function in PHP ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-3292

почти 17 лет назад

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-3292

почти 17 лет назад

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2009-3559

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3559

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3559

main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recogn ...

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-3558

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

CVSS2: 6.8
2%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-3558

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3558

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file.

CVSS2: 6.8
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3558

The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 an ...

CVSS2: 6.8
2%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-3557

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

CVSS2: 5
2%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-3557

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3557

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.

CVSS2: 5
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3557

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5 ...

CVSS2: 5
2%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-3294

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

CVSS2: 5
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3294

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

CVSS2: 5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3294

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5 ...

CVSS2: 5
3%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
redhat логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 4.3
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3293

Unspecified vulnerability in the imagecolortransparent function in PHP ...

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2009-3292

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
redhat логотип
CVE-2009-3292

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

CVSS2: 4.3
3%
Низкий
почти 17 лет назад

Уязвимостей на страницу