CVE-2008-2108
- EPSS 5.61%
- Veröffentlicht 07.05.2008 21:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy a...
- EPSS 49.74%
- Veröffentlicht 05.05.2008 17:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
- EPSS 6.65%
- Veröffentlicht 05.05.2008 17:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the FastCGI SAPI (fastcgi.c) in PHP before 5.2.6 has unknown impact and attack vectors.
- EPSS 6.49%
- Veröffentlicht 05.05.2008 17:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."
- EPSS 2.37%
- Veröffentlicht 27.03.2008 17:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service and possibly have unspecified other impact via a printf format parameter with a large width specifier, related to the php_sprintf_appendstring f...
- EPSS 13.18%
- Veröffentlicht 25.01.2008 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vuln...
CVE-2008-0145
- EPSS 0.76%
- Veröffentlicht 08.01.2008 19:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.
CVE-2007-5899
- EPSS 1.99%
- Veröffentlicht 20.11.2007 19:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as ...
CVE-2007-6039
- EPSS 0.34%
- Veröffentlicht 20.11.2007 19:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the ...
CVE-2007-5898
- EPSS 5.41%
- Veröffentlicht 20.11.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465.