Vulnerabilities > PHP > PHP > 5.2.8

DATE CVE VULNERABILITY TITLE RISK
2010-11-12 CVE-2009-5016 Numeric Errors vulnerability in PHP
Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.
network
php CWE-189
6.8
2010-11-09 CVE-2010-3436 Permissions, Privileges, and Access Controls vulnerability in multiple products
fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remote attackers to bypass open_basedir restrictions via vectors related to the length of a filename.
network
low complexity
php canonical CWE-264
5.0
2010-10-25 CVE-2010-3710 Resource Management Errors vulnerability in PHP
Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string.
network
php CWE-399
4.3
2010-08-20 CVE-2010-2484 Information Exposure vulnerability in PHP
The strrchr function in PHP 5.2 before 5.2.14 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.
network
low complexity
php CWE-200
5.0
2010-08-20 CVE-2010-3065 Permissions, Privileges, and Access Controls vulnerability in PHP
The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.
network
low complexity
php CWE-264
5.0
2010-06-24 CVE-2010-2225 Resource Management Errors vulnerability in PHP
Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized data, related to the PHP unserialize function.
network
low complexity
php CWE-399
7.5
2010-06-08 CVE-2010-2191 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in PHP
The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler.
network
low complexity
php CWE-119
6.4
2010-06-08 CVE-2010-2190 Information Exposure vulnerability in PHP
The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
network
low complexity
php CWE-200
5.0
2010-05-27 CVE-2010-2101 Information Exposure vulnerability in PHP
The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
network
low complexity
php CWE-200
5.0
2010-05-27 CVE-2010-2100 Information Exposure vulnerability in PHP
The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) http_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.
network
low complexity
php CWE-200
5.0