Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 000

Количество 4 000

ubuntu логотип

CVE-2007-1522

больше 19 лет назад

Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1522

больше 19 лет назад

Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1522

больше 19 лет назад

Double free vulnerability in the session extension in PHP 5.2.0 and 5. ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1521

больше 19 лет назад

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-1521

больше 19 лет назад

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-1521

больше 19 лет назад

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, a ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1484

больше 19 лет назад

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2007-1484

больше 19 лет назад

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2007-1484

больше 19 лет назад

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x ...

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2007-1475

больше 19 лет назад

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
EPSS: Низкий
nvd логотип

CVE-2007-1475

больше 19 лет назад

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
EPSS: Низкий
debian логотип

CVE-2007-1475

больше 19 лет назад

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconn ...

CVSS2: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2007-1461

больше 19 лет назад

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-1461

больше 19 лет назад

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-1461

больше 19 лет назад

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1460

больше 19 лет назад

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-1460

больше 19 лет назад

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-1460

больше 19 лет назад

The zip:// URL wrapper provided by the PECL zip extension in PHP befor ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-1454

больше 19 лет назад

ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-1454

больше 19 лет назад

ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-1522

Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1522

Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which calls the session identifier generator with an improper environment, leading to code execution when the generator is interrupted, as demonstrated by triggering a memory limit violation or certain PHP errors.

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1522

Double free vulnerability in the session extension in PHP 5.2.0 and 5. ...

CVSS2: 6.8
7%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1521

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

CVSS2: 6.8
8%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1521

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.

CVSS2: 6.8
8%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1521

Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, a ...

CVSS2: 6.8
8%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1484

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1484

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

CVSS2: 4.6
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1484

The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x ...

CVSS2: 4.6
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1475

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1475

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

CVSS2: 5.4
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1475

Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconn ...

CVSS2: 5.4
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1461

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

CVSS2: 7.8
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1461

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

CVSS2: 7.8
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1461

The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP ...

CVSS2: 7.8
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1460

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

CVSS2: 5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1460

The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

CVSS2: 5
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-1460

The zip:// URL wrapper provided by the PECL zip extension in PHP befor ...

CVSS2: 5
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-1454

ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.

CVSS2: 4.3
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-1454

ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.

CVSS2: 4.3
1%
Низкий
больше 19 лет назад

Уязвимостей на страницу