Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2007-4033EPSS 19% Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary … PHP No fix yet Fix from $1,9502007-07-27 MEDIUM 5.0 CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwri… PHP Mitigation only Fix from $1,6002007-06-13 MEDIUM 5.0 CVE-2007-2728 The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the m… PHP No fix yet Fix from $1,6002007-05-16 HIGH 7.5 CVE-2007-1864 Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors. PHP 4.4.7 / 5.2.2+ Fix from $1,9502007-05-09 MEDIUM 5.0 CVE-2007-2369EPSS 8% Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbi… PHP after 4.2.3 Fix from $1,6002007-04-30 CRITICAL 9.8 CVE-2007-1399EPSS 20% Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to … PHP 1.8.4+ Fix from $2,3002007-03-10 MEDIUM 6.8 CVE-2007-1382 The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demo… Com Extensions No fix yet Fix from $1,6002007-03-10 HIGH 7.5 CVE-2007-1285EPSS 18% The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) … PHP 4.4.7 / 5.2.2+ Fix from $1,9502007-03-06 HIGH 10.0 CVE-2007-0910 Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors. PHP after 5.2.0 Fix from $1,9502007-02-13 HIGH 7.5 CVE-2007-0905 PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is po… PHP Patch available Fix from $1,9502007-02-13 HIGH 7.5 CVE-2007-0906EPSS 5% Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vector… PHP Patch available Fix from $1,9502007-02-13 HIGH 7.5 CVE-2007-0909 Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of… PHP Mitigation only Fix from $1,9502007-02-13 MEDIUM 5.0 CVE-2007-0907 Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function. PHP Patch available Fix from $1,6002007-02-13 HIGH 7.5 CVE-2007-0455EPSS 12% Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of se… PHP 4.4.7+ Fix from $1,9502007-01-30 HIGH 7.5 CVE-2006-6590 PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the … Ar Memberscript No fix yet Fix from $1,9502006-12-15 HIGH 7.5 CVE-2006-6592 Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] par… Bloq Mitigation only Fix from $1,9502006-12-15 HIGH 7.5 CVE-2006-6552 PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrar… Blog Cms No fix yet Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-6541 PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute ar… Animated Smiley Generator Mitigation only Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-6545 PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attack… Errordocs No fix yet Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-1559 SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provena… Php Script Index Mitigation only Fix from $1,9502006-03-31 MEDIUM 6.8 CVE-2006-1558 Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the sea… Php Script Index No fix yet Fix from $1,6002006-03-31 HIGH 7.5 CVE-2006-0144 The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirect… Pear Patch available Fix from $1,9502006-01-09 MEDIUM 5.1 CVE-2005-4154EPSS 7% Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can… Pear after 1.4.2 Fix from $1,6002005-12-11 HIGH 7.5 CVE-2005-1921EPSS 79% Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earl… Xml Rpc 1.8.5 / 4.5.4+ Fix from $1,9502005-07-05 MEDIUM 5.0 CVE-2005-1043 exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD n… PHP Patch available Fix from $1,6002005-04-14 HIGH 10.0 CVE-2004-1019EPSS 8% The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code… PHP Patch available Fix from $1,9502005-01-10 HIGH 10.0 CVE-2004-1065EPSS 10% Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a l… PHP Patch available Fix from $1,9502005-01-10 HIGH 7.5 CVE-2002-0985 Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command li… PHP after 4.2.2 Fix from $1,9502002-09-24 MEDIUM 5.0 CVE-2001-0108 PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted p… PHP Patch available Fix from $1,6002001-03-12 MEDIUM 5.0 CVE-2001-1385 The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual… PHP Patch available Fix from $1,6002001-01-12