Search CVE reports


Toggle filters

1 – 10 of 81 results


CVE-2008-7068

Low priority

Some fixes available 3 of 4

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2009-2687

Medium priority

Some fixes available 4 of 5

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-5814

Low priority

Some fixes available 4 of 6

Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-5557

Medium priority

Some fixes available 4 of 5

Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-5624

Medium priority

Some fixes available 4 of 5

PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-3660

Medium priority

Some fixes available 4 of 6

PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-3659

Medium priority

Some fixes available 4 of 6

Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-3658

Low priority

Some fixes available 4 of 6

Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2008-2829

Medium priority

Some fixes available 8 of 10

php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request,...

3 affected packages

php-imap, php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-imap — — — — —
php4 — — — — —
php5 — — — — —
Show less packages

CVE-2007-4850

Negligible priority

Some fixes available 6 of 9

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00...

2 affected packages

php4, php5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4 — — — — —
php5 — — — — —
Show less packages