- EPSS 31.59%
- Veröffentlicht 06.12.2010 20:13:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument.
CVE-2009-5016
- EPSS 3.45%
- Veröffentlicht 12.11.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 enc...
CVE-2010-3870
- EPSS 0.71%
- Veröffentlicht 12.11.2010 21:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protec...
- EPSS 3.61%
- Veröffentlicht 09.11.2010 01:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
CVE-2010-3709
- EPSS 9.92%
- Veröffentlicht 09.11.2010 01:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.
CVE-2010-3710
- EPSS 2.78%
- Veröffentlicht 25.10.2010 20:01:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) v...
CVE-2010-2950
- EPSS 0.67%
- Veröffentlicht 28.09.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not pr...
- EPSS 0.48%
- Veröffentlicht 20.08.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The strrchr function in PHP 5.2 before 5.2.14 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.
CVE-2010-2531
- EPSS 6.69%
- Veröffentlicht 20.08.2010 22:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the a...
- EPSS 0.84%
- Veröffentlicht 20.08.2010 20:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based ...