Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 768

Количество 3 768

debian логотип

CVE-2009-3546

больше 15 лет назад

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5. ...

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2009-0754

больше 16 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2009-0754

больше 21 года назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2009-0754

больше 16 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2009-0754

больше 16 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows l ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2008-2371

почти 17 лет назад

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2008-2371

почти 17 лет назад

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

EPSS: Низкий
nvd логотип

CVE-2008-2371

почти 17 лет назад

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-2371

почти 17 лет назад

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Re ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-5447

больше 17 лет назад

ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-5128

больше 17 лет назад

SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-4889

почти 18 лет назад

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-4889

почти 18 лет назад

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers t ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-4033

почти 18 лет назад

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2007-4033

почти 18 лет назад

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

EPSS: Средний
nvd логотип

CVE-2007-4033

почти 18 лет назад

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2007-4033

почти 18 лет назад

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/ ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2007-2369

около 18 лет назад

Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-1399

больше 18 лет назад

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2007-1399

больше 18 лет назад

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2009-3546

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5. ...

CVSS2: 9.3
3%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
0%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows l ...

CVSS2: 2.1
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-2371

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
redhat логотип
CVE-2008-2371

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-2371

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-2371

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Re ...

CVSS2: 7.5
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2007-5447

ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function.

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
nvd логотип
CVE-2007-5128

SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.

CVSS2: 5
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2007-4889

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997.

CVSS2: 6.8
0%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-4889

The MySQL extension in PHP 5.2.4 and earlier allows remote attackers t ...

CVSS2: 6.8
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-4033

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

CVSS2: 7.5
32%
Средний
почти 18 лет назад
redhat логотип
CVE-2007-4033

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

32%
Средний
почти 18 лет назад
nvd логотип
CVE-2007-4033

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

CVSS2: 7.5
32%
Средний
почти 18 лет назад
debian логотип
CVE-2007-4033

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/ ...

CVSS2: 7.5
32%
Средний
почти 18 лет назад
nvd логотип
CVE-2007-2369

Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

CVSS2: 5
5%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-1399

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS2: 10
30%
Средний
больше 18 лет назад
nvd логотип
CVE-2007-1399

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

CVSS2: 10
30%
Средний
больше 18 лет назад

Уязвимостей на страницу