CVE-2010-2191
- EPSS 2.41%
- Veröffentlicht 08.06.2010 00:30:01
- Zuletzt bearbeitet 16.06.2026 23:20:16
The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-de...
- EPSS 2.05%
- Veröffentlicht 27.05.2010 22:30:02
- Zuletzt bearbeitet 16.06.2026 23:19:58
The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) http_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents)...
- EPSS 2.4%
- Veröffentlicht 27.05.2010 22:30:02
- Zuletzt bearbeitet 16.06.2026 23:19:59
The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing ...
- EPSS 1.86%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 16.06.2026 23:19:58
Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction o...
CVE-2010-2094
- EPSS 12.65%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 16.06.2026 23:19:58
Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properl...
- EPSS 1.91%
- Veröffentlicht 27.05.2010 22:30:01
- Zuletzt bearbeitet 16.06.2026 23:19:58
The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption o...
- EPSS 1.43%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 16.06.2026 23:19:34
The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_funct...
- EPSS 1.08%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 16.06.2026 23:19:34
The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by...
- EPSS 3.01%
- Veröffentlicht 12.05.2010 11:46:40
- Zuletzt bearbeitet 16.06.2026 23:19:35
Stack consumption vulnerability in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (PHP crash) via a crafted first argument to the fnmatch function, as demonstrated using a long string.
- EPSS 1.19%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 16.06.2026 23:19:28
The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call,...