Search CVE reports
41 – 50 of 81 results
CVE-2007-1286
Unknown priorityInteger overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.
1 affected package
php4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
CVE-2006-6383
Unknown priorityPHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ”;” in a session_save_path argument, followed by an allowed path, which causes a parsing...
1 affected package
php4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
CVE-2006-5178
Unknown priorityRace condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after...
1 affected package
php4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
CVE-2006-4812
Unknown priorityInteger overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the...
2 affected packages
php4, php5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
php5 | — | — | — | — |
CVE-2006-4485
Unknown priorityThe stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.
2 affected packages
php4, php5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
php5 | — | — | — | — |
CVE-2006-4023
Unknown priorityThe ip2long function in PHP 5.1.4 and earlier may incorrectly validate an arbitrary string and return a valid network IP address, which allows remote attackers to obtain network information and facilitate other attacks,...
1 affected package
php4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
CVE-2006-1991
Unknown priorityThe substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.
2 affected packages
php4, php5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
php5 | — | — | — | — |
CVE-2006-1990
Unknown prioritySome fixes available 9 of 10
Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a...
2 affected packages
php4, php5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
php5 | — | — | — | — |
CVE-2006-1490
Unknown prioritySome fixes available 9 of 10
PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client,...
2 affected packages
php4, php5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
php5 | — | — | — | — |
CVE-2006-0208
Unknown priorityMultiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not...
2 affected packages
php4, php5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
php4 | — | — | — | — |
php5 | — | — | — | — |