Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 866

Количество 3 866

ubuntu логотип

CVE-2007-2727

больше 18 лет назад

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2007-2727

больше 18 лет назад

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-2727

больше 18 лет назад

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4 ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2007-2511

больше 18 лет назад

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

CVSS2: 7.2
EPSS: Низкий
redhat логотип

CVE-2007-2511

больше 18 лет назад

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

EPSS: Низкий
nvd логотип

CVE-2007-2511

больше 18 лет назад

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2007-2511

больше 18 лет назад

Buffer overflow in the user_filter_factory_create function in PHP befo ...

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2007-2510

больше 18 лет назад

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2007-2510

больше 18 лет назад

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

EPSS: Низкий
nvd логотип

CVE-2007-2510

больше 18 лет назад

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2007-2510

больше 18 лет назад

Buffer overflow in the make_http_soap_request function in PHP before 5 ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2007-2509

больше 18 лет назад

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2007-2509

больше 18 лет назад

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

EPSS: Низкий
nvd логотип

CVE-2007-2509

больше 18 лет назад

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-2509

больше 18 лет назад

CRLF injection vulnerability in the ftp_putcmd function in PHP before ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2007-1900

больше 18 лет назад

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1900

больше 18 лет назад

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-1900

больше 18 лет назад

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ex ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-1890

больше 18 лет назад

Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1890

больше 18 лет назад

Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-2727

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2727

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2727

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4 ...

CVSS2: 2.6
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2511

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

CVSS2: 7.2
0%
Низкий
больше 18 лет назад
redhat логотип
CVE-2007-2511

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2511

Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

CVSS2: 7.2
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2511

Buffer overflow in the user_filter_factory_create function in PHP befo ...

CVSS2: 7.2
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2510

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

CVSS2: 5.1
3%
Низкий
больше 18 лет назад
redhat логотип
CVE-2007-2510

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

3%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2510

Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

CVSS2: 5.1
3%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2510

Buffer overflow in the make_http_soap_request function in PHP before 5 ...

CVSS2: 5.1
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2509

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

CVSS2: 2.6
4%
Низкий
больше 18 лет назад
redhat логотип
CVE-2007-2509

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

4%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2509

CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

CVSS2: 2.6
4%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2509

CRLF injection vulnerability in the ftp_putcmd function in PHP before ...

CVSS2: 2.6
4%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1900

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.

CVSS2: 5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1900

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.

CVSS2: 5
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1900

CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ex ...

CVSS2: 5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1890

Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.

CVSS2: 7.5
5%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1890

Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.

CVSS2: 7.5
5%
Низкий
больше 18 лет назад

Уязвимостей на страницу