- EPSS 0.57%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption o...
- EPSS 0.56%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_funct...
- EPSS 0.5%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by...
- EPSS 1.66%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (PHP crash) via a crafted first argument to the fnmatch function, as demonstrated using a long string.
- EPSS 0.46%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call,...
CVE-2010-1861
- EPSS 0.36%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object's __sleep function to interrupt an internal call to the shm_put_var function, which tr...
- EPSS 0.46%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass b...
- EPSS 0.46%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass b...
CVE-2010-1866
- EPSS 1.56%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a sig...
CVE-2010-1868
- EPSS 1.04%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, wh...