CVE-2007-0905
- EPSS 1.1%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
CVE-2007-0906
- EPSS 1.5%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) s...
- EPSS 2.6%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.
- EPSS 17.06%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element ...
CVE-2007-0909
- EPSS 2.95%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.
- EPSS 6.79%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.
CVE-2007-0911
- EPSS 9.71%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).
CVE-2007-0455
- EPSS 4.93%
- Veröffentlicht 30.01.2007 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded...
CVE-2006-6383
- EPSS 0.25%
- Veröffentlicht 10.12.2006 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP v...
CVE-2006-5706
- EPSS 0.05%
- Veröffentlicht 04.11.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerabilities in PHP, probably before 5.2.0, allow local users to bypass open_basedir restrictions and perform unspecified actions via unspecified vectors involving the (1) chdir and (2) tempnam functions. NOTE: the tempnam vector migh...