5

CVE-2005-1043

exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.

Data is provided by the National Vulnerability Database (NVD)
PhpPhp Version4.3.0
PhpPhp Version4.3.1
PhpPhp Version4.3.2
PhpPhp Version4.3.3
PhpPhp Version4.3.4
PhpPhp Version4.3.5
PhpPhp Version4.3.6
PhpPhp Version4.3.7
PhpPhp Version4.3.8
PhpPhp Version4.3.9
PhpPhp Version4.3.10
SgiPropack Version3.0
ConectivaLinux Version9.0
ConectivaLinux Version10.0
ApplemacOS X Version10.3.9
ApplemacOS X Version10.4
ApplemacOS X Version10.4.1
ApplemacOS X Server Version10.3.9
ApplemacOS X Server Version10.4
ApplemacOS X Server Version10.4.1
PeachtreePeachtree Linux Versionrelease_1
SuseSuse Linux Version1.0
SuseSuse Linux Version2.0
SuseSuse Linux Version3.0
SuseSuse Linux Version4.0
SuseSuse Linux Version4.2
SuseSuse Linux Version4.3
SuseSuse Linux Version4.4
SuseSuse Linux Version4.4.1
SuseSuse Linux Version5.0
SuseSuse Linux Version5.1
SuseSuse Linux Version5.2
SuseSuse Linux Version5.3
SuseSuse Linux Version6.0
SuseSuse Linux Version6.1
SuseSuse Linux Version6.1 Updatealpha
SuseSuse Linux Version6.2
SuseSuse Linux Version6.3
SuseSuse Linux Version6.3 Editionppc
SuseSuse Linux Version6.3 Updatealpha
SuseSuse Linux Version6.4
SuseSuse Linux Version6.4 Editioni386
SuseSuse Linux Version6.4 Editionppc
SuseSuse Linux Version6.4 Updatealpha
SuseSuse Linux Version7.0
SuseSuse Linux Version7.0 Editioni386
SuseSuse Linux Version7.0 Editionppc
SuseSuse Linux Version7.0 Editionsparc
SuseSuse Linux Version7.0 Updatealpha
SuseSuse Linux Version7.1
SuseSuse Linux Version7.1 Editionspa
SuseSuse Linux Version7.1 Editionsparc
SuseSuse Linux Version7.1 Editionx86
SuseSuse Linux Version7.1 Updatealpha
SuseSuse Linux Version7.2
SuseSuse Linux Version7.2 Editioni386
SuseSuse Linux Version7.3
SuseSuse Linux Version7.3 Editioni386
SuseSuse Linux Version7.3 Editionppc
SuseSuse Linux Version7.3 Editionsparc
SuseSuse Linux Version8.0
SuseSuse Linux Version8.0 Editioni386
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2
SuseSuse Linux Version9.0
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1
SuseSuse Linux Version9.1 Editionx86_64
SuseSuse Linux Version9.2
SuseSuse Linux Version9.2 Editionx86_64
SuseSuse Linux Version9.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.23% 0.785
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P