← Back

Php

php

Vendor: Php • 724 CVEs

CVEs (724)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Php
1Php
Apr 23, 2026
Mar 6, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.
5Canonical
NovellPhp+2 more
7Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+4 more
Apr 23, 2026
Mar 6, 2007
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable...Show more
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 23, 2026
Feb 20, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain intege...Show more
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-bit arguments to be used after the check for a negative value, as demonstrated by an "a:2147483649:{" argument.Show less
1Php
1Php
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).
2Php
Trustix
2Php
Secure Linux
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.
2Php
Trustix
2Php
Secure Linux
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all fu...Show more
Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack me...Show more
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.Show less
2Php
Trustix
2Php
Secure Linux
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer underflow in PHP before 5.2.1 allows attackers to cause a denial of service via unspecified vectors involving the sapi_header_op function.
2Php
Trustix
2Php
Secure Linux
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5)...Show more
Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) str_replace, (7) mail, (8) ibase_delete_user, (9) ibase_add_user, and (10) ibase_modify_user functions. NOTE: vector 6 might actually be an integer overflow (CVE-2007-1885). NOTE: as of 20070411, vector (3) might involve the imap_mail_compose function (CVE-2007-1825).Show less
2Php
Trustix
2Php
Secure Linux
Apr 23, 2026
Feb 13, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
5Canonical
FedoraprojectGd Graphics Library Project+2 more
7Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+4 more
Apr 23, 2026
Jan 30, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...Show more
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.Show less
1Php
1Php
Apr 23, 2026
Dec 10, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsin...Show more
PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.Show less
1Php
1Php
Apr 23, 2026
Nov 4, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerabilities in PHP, probably before 5.2.0, allow local users to bypass open_basedir restrictions and perform unspecified actions via unspecified vectors involving the (1) chdir and (2) tempnam functions....Show more
Unspecified vulnerabilities in PHP, probably before 5.2.0, allow local users to bypass open_basedir restrictions and perform unspecified actions via unspecified vectors involving the (1) chdir and (2) tempnam functions. NOTE: the tempnam vector might overlap CVE-2006-1494.Show less
1Php
1Php
Apr 23, 2026
Nov 4, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions.
1Php
1Php
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the o...Show more
Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.Show less
1Php
1Php
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which trigge...Show more
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).Show less
1Php
1Php
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
3.6 LOW· v2
PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php...Show more
PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.Show less
1Php
1Php
Apr 16, 2026
Aug 31, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.
1Php
1Php
Apr 16, 2026
Aug 31, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.
1Php
1Php
Apr 16, 2026
Aug 31, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_...Show more
Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.Show less