CVE-2011-1148
- EPSS 4.74%
- Veröffentlicht 18.03.2011 15:55:01
- Zuletzt bearbeitet 16.06.2026 23:28:49
Use-after-free vulnerability in the substr_replace function in PHP 5.3.6 and earlier allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by using the same variable for multiple...
CVE-2011-1153
- EPSS 6.83%
- Veröffentlicht 16.03.2011 22:55:04
- Zuletzt bearbeitet 16.06.2026 23:28:49
Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and earlier allow context-dependent attackers to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly e...
CVE-2011-1092
- EPSS 17.88%
- Veröffentlicht 15.03.2011 17:55:04
- Zuletzt bearbeitet 16.06.2026 23:28:41
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read sensitive memory via a large third argument to the shmop_read function.
- EPSS 14.41%
- Veröffentlicht 19.02.2011 01:00:02
- Zuletzt bearbeitet 16.06.2026 23:27:19
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependent attackers to cause a denial of service (crash) via an invalid size argument, which triggers a NULL pointer dereference.
CVE-2011-0753
- EPSS 0.8%
- Veröffentlicht 02.02.2011 22:00:02
- Zuletzt bearbeitet 16.06.2026 23:28:00
Race condition in the PCNTL extension in PHP before 5.3.4, when a user-defined signal handler exists, might allow context-dependent attackers to cause a denial of service (memory corruption) via a large number of concurrent signals.
CVE-2011-0754
- EPSS 0.34%
- Veröffentlicht 02.02.2011 22:00:02
- Zuletzt bearbeitet 16.06.2026 23:28:00
The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform d...
- EPSS 1.94%
- Veröffentlicht 02.02.2011 22:00:02
- Zuletzt bearbeitet 16.06.2026 23:28:00
Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a large max parameter, as demonstrated by a value that exceeds mt_getrandma...
- EPSS 1.34%
- Veröffentlicht 02.02.2011 22:00:01
- Zuletzt bearbeitet 16.06.2026 23:28:00
The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions b...
- EPSS 5.36%
- Veröffentlicht 18.01.2011 20:00:10
- Zuletzt bearbeitet 16.06.2026 22:34:39
PHP before 5.3.4 accepts the \0 character in a pathname, which might allow context-dependent attackers to bypass intended access restrictions by placing a safe file extension after this character, as demonstrated by .php\0.jpg at the end of the argum...
CVE-2010-4697
- EPSS 2.27%
- Veröffentlicht 18.01.2011 20:00:10
- Zuletzt bearbeitet 16.06.2026 23:25:22
Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of _...