CVE-2011-4566
- EPSS 6.56%
- Veröffentlicht 29.11.2011 00:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:03
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_v...
CVE-2011-3379
- EPSS 5.01%
- Veröffentlicht 03.11.2011 15:55:00
- Zuletzt bearbeitet 16.06.2026 23:33:11
The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages a...
- EPSS 2.87%
- Veröffentlicht 25.08.2011 18:55:01
- Zuletzt bearbeitet 16.06.2026 23:32:59
PHP before 5.3.7 does not properly implement the error_log function, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors.
- EPSS 5.72%
- Veröffentlicht 25.08.2011 18:55:01
- Zuletzt bearbeitet 16.06.2026 23:32:59
Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.
CVE-2011-3189
- EPSS 4.21%
- Veröffentlicht 25.08.2011 14:22:48
- Zuletzt bearbeitet 16.06.2026 23:32:50
The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability tha...
- EPSS 19.15%
- Veröffentlicht 25.08.2011 14:22:47
- Zuletzt bearbeitet 16.06.2026 23:32:49
PHP before 5.3.7 does not properly check the return values of the malloc, calloc, and realloc library functions, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger a buffe...
- EPSS 5.15%
- Veröffentlicht 25.08.2011 14:22:44
- Zuletzt bearbeitet 16.06.2026 23:29:45
The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions in ext/zip/php_zip.c in PHP 5.3.6 allow context-dependent attackers to cause a denial of service (application crash) via certain flags arguments, as demonstrated by (a) GLOB_ALTDIRF...
- EPSS 4.97%
- Veröffentlicht 25.08.2011 14:22:44
- Zuletzt bearbeitet 16.06.2026 23:31:25
crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext passwo...
CVE-2011-2202
- EPSS 19.74%
- Veröffentlicht 16.06.2011 23:55:04
- Zuletzt bearbeitet 16.06.2026 23:30:54
The rfc1867_post_handler function in main/rfc1867.c in PHP before 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote attackers to conduct absolute path traversal attacks, and possibly create or overwr...
CVE-2011-1938
- EPSS 23.13%
- Veröffentlicht 31.05.2011 20:55:05
- Zuletzt bearbeitet 16.06.2026 23:30:25
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might allow context-dependent attackers to execute arbitrary code via a long pathname for a UNIX socket.