CVE-2010-2225
- EPSS 2.19%
- Veröffentlicht 24.06.2010 12:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.
- EPSS 0.56%
- Veröffentlicht 08.06.2010 00:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an interna...
CVE-2010-2191
- EPSS 1.26%
- Veröffentlicht 08.06.2010 00:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-de...
- EPSS 0.92%
- Veröffentlicht 27.05.2010 22:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) http_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents)...
- EPSS 1.12%
- Veröffentlicht 27.05.2010 22:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing ...
- EPSS 0.42%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction o...
CVE-2010-2094
- EPSS 3.09%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properl...
- EPSS 0.57%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption o...
- EPSS 0.54%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_funct...
- EPSS 0.46%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by...