Search CVE reports


Toggle filters

21 – 30 of 81 results


CVE-2006-7204

Unknown priority
Not affected

The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users to read arbitrary files or list arbitrary directory contents.

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1890

Unknown priority
Ignored

Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as...

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1884

Unknown priority
Ignored

Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers...

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1883

Unknown priority
Ignored

PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer,...

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1835

Unknown priority
Ignored

PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1825

Unknown priority
Ignored

Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it...

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1777

Unknown priority
Ignored

Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in...

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1711

Unknown priority
Ignored

Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. ...

1 affected package

php4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
Show less packages

CVE-2007-1710

Unknown priority
Not affected

The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax,...

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2007-1701

Unknown priority
Not affected

PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as...

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages