Search CVE reports


Toggle filters

531 – 540 of 656 results


CVE-2007-4660

Low priority
Fixed

Unspecified vulnerability in the chunk_split function in PHP before 5.2.4 has unknown impact and attack vectors, related to an incorrect size calculation.

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2007-4659

Low priority
Ignored

The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2007-4658

Medium priority
Fixed

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2007-4652

Negligible priority
Ignored

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages

CVE-2007-3997

Negligible priority
Ignored

The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with...

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2007-3996

Medium priority

Some fixes available 6 of 8

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the...

2 affected packages

libgd2, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libgd2
php5
Show less packages

CVE-2007-4657

Medium priority

Some fixes available 4 of 6

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn...

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2007-3998

Medium priority

Some fixes available 4 of 6

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or...

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2007-4596

Negligible priority
Ignored

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.

2 affected packages

php4, php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php4
php5
Show less packages

CVE-2007-4255

Low priority
Not affected

Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a long first argument to the msql_connect function.

1 affected package

php5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php5
Show less packages