CVE-2010-3710
- EPSS 3.09%
- Veröffentlicht 25.10.2010 20:01:03
- Zuletzt bearbeitet 16.06.2026 23:23:23
Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) v...
CVE-2010-2950
- EPSS 5.69%
- Veröffentlicht 28.09.2010 18:00:02
- Zuletzt bearbeitet 16.06.2026 23:21:49
Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not pr...
- EPSS 1.83%
- Veröffentlicht 20.08.2010 22:00:01
- Zuletzt bearbeitet 16.06.2026 23:20:50
The strrchr function in PHP 5.2 before 5.2.14 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.
CVE-2010-2531
- EPSS 5%
- Veröffentlicht 20.08.2010 22:00:01
- Zuletzt bearbeitet 16.06.2026 23:20:55
The var_export function in PHP 5.2 before 5.2.14 and 5.3 before 5.3.3 flushes the output buffer to the user when certain fatal errors occur, even if display_errors is off, which allows remote attackers to obtain sensitive information by causing the a...
- EPSS 2.6%
- Veröffentlicht 20.08.2010 20:00:03
- Zuletzt bearbeitet 16.06.2026 23:22:03
mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based ...
- EPSS 1.57%
- Veröffentlicht 20.08.2010 20:00:03
- Zuletzt bearbeitet 16.06.2026 23:22:03
The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that caus...
CVE-2010-3064
- EPSS 2.37%
- Veröffentlicht 20.08.2010 20:00:03
- Zuletzt bearbeitet 16.06.2026 23:22:03
Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username o...
- EPSS 2.45%
- Veröffentlicht 20.08.2010 20:00:03
- Zuletzt bearbeitet 16.06.2026 23:22:03
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
CVE-2010-2225
- EPSS 5.34%
- Veröffentlicht 24.06.2010 12:30:01
- Zuletzt bearbeitet 16.06.2026 23:20:20
Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.
- EPSS 1.9%
- Veröffentlicht 08.06.2010 00:30:01
- Zuletzt bearbeitet 16.06.2026 23:20:15
The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an interna...