Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 863

Количество 3 863

redhat логотип

CVE-2004-1018

больше 20 лет назад

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

EPSS: Средний
nvd логотип

CVE-2004-1018

больше 20 лет назад

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2004-1018

больше 20 лет назад

Multiple integer handling errors in PHP before 4.3.10 allow attackers ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0959

почти 21 год назад

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2004-0959

почти 21 год назад

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

EPSS: Низкий
nvd логотип

CVE-2004-0959

почти 21 год назад

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2004-0959

почти 21 год назад

rfc1867.c in PHP before 5.0.2 allows local users to upload files to ar ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0958

почти 21 год назад

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2004-0958

почти 21 год назад

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

EPSS: Средний
nvd логотип

CVE-2004-0958

почти 21 год назад

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2004-0958

почти 21 год назад

php_variables.c in PHP before 5.0.2 allows remote attackers to read se ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0542

около 21 года назад

PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2004-0542

около 21 года назад

PHP before 4.3.7 on Win32 platforms does not properly filter all shell ...

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2003-1303

около 22 лет назад

Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.

EPSS: Низкий
nvd логотип

CVE-2003-1303

больше 21 года назад

Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2003-1302

больше 22 лет назад

The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.

EPSS: Низкий
nvd логотип

CVE-2003-1302

больше 21 года назад

The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2003-1302

больше 21 года назад

The IMAP functionality in PHP before 4.3.1 allows remote attackers to ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0863

почти 22 года назад

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2003-0863

почти 22 года назад

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2004-1018

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

37%
Средний
больше 20 лет назад
nvd логотип
CVE-2004-1018

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

CVSS2: 10
37%
Средний
больше 20 лет назад
debian логотип
CVE-2004-1018

Multiple integer handling errors in PHP before 4.3.10 allow attackers ...

CVSS2: 10
37%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2004-0959

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

CVSS2: 2.1
5%
Низкий
почти 21 год назад
redhat логотип
CVE-2004-0959

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

5%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0959

rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

CVSS2: 2.1
5%
Низкий
почти 21 год назад
debian логотип
CVE-2004-0959

rfc1867.c in PHP before 5.0.2 allows local users to upload files to ar ...

CVSS2: 2.1
5%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2004-0958

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

CVSS2: 5
11%
Средний
почти 21 год назад
redhat логотип
CVE-2004-0958

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

11%
Средний
почти 21 год назад
nvd логотип
CVE-2004-0958

php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

CVSS2: 5
11%
Средний
почти 21 год назад
debian логотип
CVE-2004-0958

php_variables.c in PHP before 5.0.2 allows remote attackers to read se ...

CVSS2: 5
11%
Средний
почти 21 год назад
nvd логотип
CVE-2004-0542

PHP before 4.3.7 on Win32 platforms does not properly filter all shell metacharacters, which allows local or remote attackers to execute arbitrary code, overwrite files, and access internal environment variables via (1) the "%", "|", or ">" characters to the escapeshellcmd function, or (2) the "%" character to the escapeshellarg function.

CVSS2: 10
8%
Низкий
около 21 года назад
debian логотип
CVE-2004-0542

PHP before 4.3.7 on Win32 platforms does not properly filter all shell ...

CVSS2: 10
8%
Низкий
около 21 года назад
redhat логотип
CVE-2003-1303

Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.

2%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-1303

Buffer overflow in the imap_fetch_overview function in the IMAP functionality (php_imap.c) in PHP before 4.3.3 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long e-mail address in a (1) To or (2) From header.

CVSS2: 5
2%
Низкий
больше 21 года назад
redhat логотип
CVE-2003-1302

The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.

1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1302

The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.

CVSS2: 5
1%
Низкий
больше 21 года назад
debian логотип
CVE-2003-1302

The IMAP functionality in PHP before 4.3.1 allows remote attackers to ...

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-0863

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

CVSS2: 7.5
3%
Низкий
почти 22 года назад
debian логотип
CVE-2003-0863

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PH ...

CVSS2: 7.5
3%
Низкий
почти 22 года назад

Уязвимостей на страницу