CVE-2009-3546
- EPSS 3.55%
- Published 19.10.2009 20:00:00
- Last modified 09.04.2025 00:30:58
The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-...
CVE-2009-3291
- EPSS 1.87%
- Published 22.09.2009 10:30:00
- Last modified 09.04.2025 00:30:58
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
CVE-2009-3292
- EPSS 3.61%
- Published 22.09.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."
CVE-2009-3293
- EPSS 1.81%
- Published 22.09.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."
- EPSS 1.89%
- Published 22.09.2009 10:30:00
- Last modified 09.04.2025 00:30:58
The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" stri...
CVE-2008-7068
- EPSS 0.4%
- Published 25.08.2009 10:30:00
- Last modified 09.04.2025 00:30:58
The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in which the attacker can...
CVE-2008-7002
- EPSS 0.05%
- Published 19.08.2009 05:24:52
- Last modified 09.04.2025 00:30:58
PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) ...
CVE-2009-2687
- EPSS 10.74%
- Published 05.08.2009 19:30:01
- Last modified 09.04.2025 00:30:58
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
- EPSS 10.22%
- Published 08.04.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.
- EPSS 2.17%
- Published 08.04.2009 18:30:00
- Last modified 09.04.2025 00:30:58
The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during ex...