Vulnerabilities > PHP > PHP > 4.4.8
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-05-05 | CVE-2008-0599 | Incorrect Calculation of Buffer Size vulnerability in multiple products The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI. | 9.8 |
2008-03-27 | CVE-2008-1384 | Numeric Errors vulnerability in PHP Integer overflow in PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service and possibly have unspecified other impact via a printf format parameter with a large width specifier, related to the php_sprintf_appendstring function in formatted_print.c and probably other functions for formatted strings (aka *printf functions). | 5.0 |
2007-11-20 | CVE-2007-6039 | Improper Input Validation vulnerability in PHP PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. | 2.1 |
2007-11-20 | CVE-2007-5899 | Information Exposure vulnerability in PHP The output_add_rewrite_var function in PHP before 5.2.5 rewrites local forms in which the ACTION attribute references a non-local URL, which allows remote attackers to obtain potentially sensitive information by reading the requests for this URL, as demonstrated by a rewritten form containing a local session ID. | 4.3 |
2007-11-20 | CVE-2007-5900 | Permissions, Privileges, and Access Controls vulnerability in PHP PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625. | 6.9 |
2007-11-20 | CVE-2007-5898 | Unspecified vulnerability in PHP The (1) htmlentities and (2) htmlspecialchars functions in PHP before 5.2.5 accept partial multibyte sequences, which has unknown impact and attack vectors, a different issue than CVE-2006-5465. | 6.4 |
2007-09-27 | CVE-2007-5128 | Improper Input Validation vulnerability in multiple products SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows. | 5.0 |
2007-09-14 | CVE-2007-4889 | Security Bypass vulnerability in PHP The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions via the MySQL (1) LOAD_FILE, (2) INTO DUMPFILE, and (3) INTO OUTFILE functions, a different issue than CVE-2007-3997. network php | 6.8 |
2007-09-14 | CVE-2007-4887 | Improper Input Validation vulnerability in PHP The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. | 4.3 |
2007-09-12 | CVE-2007-4840 | Improper Input Validation vulnerability in PHP PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. | 5.0 |