Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3 999

Количество 3 999

redhat логотип

CVE-2006-1990

больше 20 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

EPSS: Низкий
nvd логотип

CVE-2006-1990

больше 20 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-1990

больше 20 лет назад

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-1608

больше 20 лет назад

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-1608

больше 20 лет назад

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2006-1608

больше 20 лет назад

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1549

больше 20 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-1549

больше 20 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2006-1549

больше 20 лет назад

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

EPSS: Низкий
nvd логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-1494

больше 20 лет назад

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 all ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

EPSS: Средний
nvd логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2006-1490

больше 20 лет назад

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions o ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-1017

больше 20 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2006-1017

больше 20 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2006-1015

больше 20 лет назад

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2006-1990

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

8%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1990

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

CVSS2: 5
8%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1990

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and ...

CVSS2: 5
8%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1608

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1608

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1608

The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users ...

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1549

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1549

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1549

PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation ...

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
6%
Низкий
больше 20 лет назад
redhat логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

6%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

CVSS2: 2.6
6%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1494

Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 all ...

CVSS2: 2.6
6%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
21%
Средний
больше 20 лет назад
redhat логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

21%
Средний
больше 20 лет назад
nvd логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

CVSS2: 5
21%
Средний
больше 20 лет назад
debian логотип
CVE-2006-1490

PHP before 5.1.3-RC1 might allow remote attackers to obtain portions o ...

CVSS2: 5
21%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1015

Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

CVSS2: 6.4
12%
Средний
больше 20 лет назад

Уязвимостей на страницу