Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4 010

Количество 4 010

ubuntu логотип

CVE-2006-5178

почти 20 лет назад

Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2006-5178

почти 20 лет назад

Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

CVSS2: 6.2
EPSS: Низкий
debian логотип

CVE-2006-5178

почти 20 лет назад

Race condition in the symlink function in PHP 5.1.6 and earlier allows ...

CVSS2: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2006-4812

почти 20 лет назад

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

CVSS2: 10
EPSS: Средний
redhat логотип

CVE-2006-4812

почти 20 лет назад

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

EPSS: Средний
nvd логотип

CVE-2006-4812

почти 20 лет назад

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2006-4812

почти 20 лет назад

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2006-4625

около 20 лет назад

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

CVSS2: 3.6
EPSS: Низкий
redhat логотип

CVE-2006-4625

около 20 лет назад

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

EPSS: Низкий
nvd логотип

CVE-2006-4625

около 20 лет назад

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

CVSS2: 3.6
EPSS: Низкий
debian логотип

CVE-2006-4625

около 20 лет назад

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass ...

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2006-4486

около 20 лет назад

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2006-4486

около 20 лет назад

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

EPSS: Низкий
nvd логотип

CVE-2006-4486

около 20 лет назад

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-4486

около 20 лет назад

Integer overflow in memory allocation routines in PHP before 5.1.6, wh ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-4485

около 20 лет назад

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2006-4485

около 20 лет назад

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

EPSS: Низкий
nvd логотип

CVE-2006-4485

около 20 лет назад

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2006-4485

около 20 лет назад

The stripos function in PHP before 5.1.5 has unknown impact and attack ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2006-4484

около 20 лет назад

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2006-5178

Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

CVSS2: 6.2
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-5178

Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

CVSS2: 6.2
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2006-5178

Race condition in the symlink function in PHP 5.1.6 and earlier allows ...

CVSS2: 6.2
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2006-4812

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

CVSS2: 10
20%
Средний
почти 20 лет назад
redhat логотип
CVE-2006-4812

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

20%
Средний
почти 20 лет назад
nvd логотип
CVE-2006-4812

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

CVSS2: 10
20%
Средний
почти 20 лет назад
debian логотип
CVE-2006-4812

Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote ...

CVSS2: 10
20%
Средний
почти 20 лет назад
ubuntu логотип
CVE-2006-4625

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

CVSS2: 3.6
1%
Низкий
около 20 лет назад
redhat логотип
CVE-2006-4625

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

1%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-4625

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

CVSS2: 3.6
1%
Низкий
около 20 лет назад
debian логотип
CVE-2006-4625

PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass ...

CVSS2: 3.6
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-4486

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

CVSS2: 2.6
2%
Низкий
около 20 лет назад
redhat логотип
CVE-2006-4486

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

2%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-4486

Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.

CVSS2: 2.6
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-4486

Integer overflow in memory allocation routines in PHP before 5.1.6, wh ...

CVSS2: 2.6
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-4485

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

CVSS2: 10
2%
Низкий
около 20 лет назад
redhat логотип
CVE-2006-4485

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

2%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-4485

The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.

CVSS2: 10
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-4485

The stripos function in PHP before 5.1.5 has unknown impact and attack ...

CVSS2: 10
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-4484

Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.

CVSS2: 2.6
9%
Низкий
около 20 лет назад

Уязвимостей на страницу