Vulnerabilities > PHP > PHP > 5.2.0

DATE CVE VULNERABILITY TITLE RISK
2007-03-06 CVE-2007-1285 Uncontrolled Recursion vulnerability in multiple products
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
network
low complexity
php canonical novell suse redhat CWE-674
7.5
2007-02-20 CVE-2007-0988 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.
4.3
2007-02-13 CVE-2007-0910 Multiple vulnerability in PHP 5.2.0 and Prior Versions
Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.
network
low complexity
php trustix
critical
10.0
2007-02-13 CVE-2007-0909 Multiple vulnerability in PHP 5.2.0 and Prior Versions
Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.
network
low complexity
php trustix
7.5
2007-02-13 CVE-2007-0908 Improper Input Validation vulnerability in multiple products
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.
network
low complexity
php canonical CWE-20
5.0
2007-02-13 CVE-2007-0907 Multiple vulnerability in PHP 5.2.0 and Prior Versions
Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.
network
low complexity
php trustix
5.0
2007-02-13 CVE-2007-0906 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions.
network
low complexity
php trustix CWE-119
7.5
2007-02-13 CVE-2007-0905 Multiple vulnerability in PHP 5.2.0 and Prior Versions
PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension.
network
low complexity
php trustix
7.5
2006-12-10 CVE-2006-6383 Improper Input Validation vulnerability in PHP 4.4.0/5.2.0
PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.
local
low complexity
php CWE-20
4.6