Search CVE reports


Toggle filters

481 – 490 of 656 results


CVE-2009-3557

Low priority
Fixed

The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2009-3546

Medium priority
Fixed

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer...

2 affected packages

libgd2, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2
php5
Show less packages

CVE-2009-3294

Medium priority
Not affected

The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1)...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2009-3293

Low priority
Fixed

Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

2 affected packages

libgd2, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2
php5
Show less packages

CVE-2009-3292

Low priority
Fixed

Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2009-3291

Low priority
Fixed

The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2008-7068

Low priority

Some fixes available 3 of 4

The dba_replace function in PHP 5.2.6 and 4.x allows context-dependent attackers to cause a denial of service (file truncation) via a key with the NULL byte. NOTE: this might only be a vulnerability in limited circumstances in...

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2008-7002

Low priority
Ignored

PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2009-2687

Medium priority

Some fixes available 4 of 5

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2009-1272

Medium priority
Not affected

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not...

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages