Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP HIGH 7.5
CVE-2007-4033EPSS 19%

Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary …

No fix yet
Fix from $1,950 2007-07-27
PHP MEDIUM 5.0
CVE-2007-3205

The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwri…

Mitigation only
Fix from $1,600 2007-06-13
PHP MEDIUM 5.0
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the m…

No fix yet
Fix from $1,600 2007-05-16
PHP HIGH 7.5
CVE-2007-1864

Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.

Fix: 4.4.7 / 5.2.2+
Fix from $1,950 2007-05-09
PHP MEDIUM 5.0
CVE-2007-2369EPSS 8%

Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbi…

Fix: after 4.2.3
Fix from $1,600 2007-04-30
PHP CRITICAL 9.8
CVE-2007-1399EPSS 20%

Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to …

Fix: 1.8.4+
Fix from $2,300 2007-03-10
Com Extensions MEDIUM 6.8
CVE-2007-1382

The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demo…

No fix yet
Fix from $1,600 2007-03-10
PHP HIGH 7.5
CVE-2007-1285EPSS 18%

The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) …

Fix: 4.4.7 / 5.2.2+
Fix from $1,950 2007-03-06
PHP HIGH 10.0
CVE-2007-0910

Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.

Fix: after 5.2.0
Fix from $1,950 2007-02-13
PHP HIGH 7.5
CVE-2007-0905

PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is po…

Patch available
Fix from $1,950 2007-02-13
PHP HIGH 7.5
CVE-2007-0906EPSS 5%

Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vector…

Patch available
Fix from $1,950 2007-02-13
PHP HIGH 7.5
CVE-2007-0909

Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of…

Mitigation only
Fix from $1,950 2007-02-13
PHP MEDIUM 5.0
CVE-2007-0907

Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.

Patch available
Fix from $1,600 2007-02-13
PHP HIGH 7.5
CVE-2007-0455EPSS 12%

Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of se…

Fix: 4.4.7+
Fix from $1,950 2007-01-30
Ar Memberscript HIGH 7.5
CVE-2006-6590

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,950 2006-12-15
Bloq HIGH 7.5
CVE-2006-6592

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] par…

Mitigation only
Fix from $1,950 2006-12-15
Blog Cms HIGH 7.5
CVE-2006-6552

PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2006-12-14
Animated Smiley Generator HIGH 7.5
CVE-2006-6541

PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2006-12-14
Errordocs HIGH 7.5
CVE-2006-6545

PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attack…

No fix yet
Fix from $1,950 2006-12-14
Php Script Index HIGH 7.5
CVE-2006-1559

SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provena…

Mitigation only
Fix from $1,950 2006-03-31
Php Script Index MEDIUM 6.8
CVE-2006-1558

Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the sea…

No fix yet
Fix from $1,600 2006-03-31
Pear HIGH 7.5
CVE-2006-0144

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirect…

Patch available
Fix from $1,950 2006-01-09
Pear MEDIUM 5.1
CVE-2005-4154EPSS 7%

Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can…

Fix: after 1.4.2
Fix from $1,600 2005-12-11
Xml Rpc HIGH 7.5
CVE-2005-1921EPSS 79%

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earl…

Fix: 1.8.5 / 4.5.4+
Fix from $1,950 2005-07-05
PHP MEDIUM 5.0
CVE-2005-1043

exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD n…

Patch available
Fix from $1,600 2005-04-14
PHP HIGH 10.0
CVE-2004-1019EPSS 8%

The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code…

Patch available
Fix from $1,950 2005-01-10
PHP HIGH 10.0
CVE-2004-1065EPSS 10%

Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a l…

Patch available
Fix from $1,950 2005-01-10
PHP HIGH 7.5
CVE-2002-0985

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command li…

Fix: after 4.2.2
Fix from $1,950 2002-09-24
PHP MEDIUM 5.0
CVE-2001-0108

PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted p…

Patch available
Fix from $1,600 2001-03-12
PHP MEDIUM 5.0
CVE-2001-1385

The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual…

Patch available
Fix from $1,600 2001-01-12