Логотип exploitDog
product: "php"
Консоль
Логотип exploitDog

exploitDog

product: "php"

Количество 3 889

Количество 3 889

ubuntu логотип

CVE-2011-4078

больше 14 лет назад

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4078

больше 14 лет назад

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4078

больше 14 лет назад

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5. ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-1939

больше 6 лет назад

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2011-1939

больше 6 лет назад

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2011-1939

больше 6 лет назад

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4156

больше 15 лет назад

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2010-4156

больше 15 лет назад

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2010-4156

больше 15 лет назад

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2010-4156

больше 15 лет назад

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2009-3546

больше 16 лет назад

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
EPSS: Низкий
redhat логотип

CVE-2009-3546

больше 16 лет назад

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2009-3546

больше 16 лет назад

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2009-3546

больше 16 лет назад

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5. ...

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2009-0754

около 17 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2009-0754

около 22 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2009-0754

около 17 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2009-0754

около 17 лет назад

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows l ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2008-2371

больше 17 лет назад

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2008-2371

почти 18 лет назад

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-4078

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-4078

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5.3.7 or 5.3.8 is used, allows remote attackers to trigger a GET request for an arbitrary URL, and cause a denial of service (resource consumption and inbox outage), via a Subject header containing only a URL, a related issue to CVE-2011-3379.

CVSS2: 5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-4078

include/iniset.php in Roundcube Webmail 0.5.4 and earlier, when PHP 5. ...

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-1939

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
6%
Низкий
больше 6 лет назад
nvd логотип
CVE-2011-1939

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

CVSS3: 9.8
6%
Низкий
больше 6 лет назад
debian логотип
CVE-2011-1939

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and ...

CVSS3: 9.8
6%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2010-4156

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

CVSS2: 5
10%
Средний
больше 15 лет назад
redhat логотип
CVE-2010-4156

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

CVSS2: 4.3
10%
Средний
больше 15 лет назад
nvd логотип
CVE-2010-4156

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

CVSS2: 5
10%
Средний
больше 15 лет назад
debian логотип
CVE-2010-4156

The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through ...

CVSS2: 5
10%
Средний
больше 15 лет назад
ubuntu логотип
CVE-2009-3546

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
4%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-3546

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

CVSS2: 4.4
4%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3546

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
4%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3546

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5. ...

CVSS2: 9.3
4%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
0%
Низкий
около 17 лет назад
redhat логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

CVSS2: 2.1
0%
Низкий
около 17 лет назад
debian логотип
CVE-2009-0754

PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows l ...

CVSS2: 2.1
0%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-2371

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

CVSS2: 7.5
4%
Низкий
больше 17 лет назад
redhat логотип
CVE-2008-2371

Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

4%
Низкий
почти 18 лет назад

Уязвимостей на страницу