![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-3018
https://notcve.org/view.php?id=CVE-2006-3018
14 Jun 2006 — Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption. Vulnerabilidad no especificada en la funcionalidad de extensión de sesión en PHP anterior a la versión 5.1.3 tiene un impacto y vectores de ataque desconocidos, relacionados con una corrupción de memoria dinámica. • http://secunia.com/advisories/19927 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-3017
https://notcve.org/view.php?id=CVE-2006-3017
14 Jun 2006 — zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations. • ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-3016
https://notcve.org/view.php?id=CVE-2006-3016
14 Jun 2006 — Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters that are frequently associated with CRLF injection, SQL injection, cross-site scripting (XSS), and HTTP response splitting vulnerabilities. NOTE: while the nature of the vulnerability is unspecified, it is likely that this is related to a violation of an expectation by PHP applications that the session name is alphanumeric, as implie... • ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-2660
https://notcve.org/view.php?id=CVE-2006-2660
13 Jun 2006 — Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 and 4.x before 4.4.3 allows local users to bypass restrictions and create PHP files with fixed names in other directories via a pathname argument longer than MAXPATHLEN, which prevents a unique string from being appended to the filename. • http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0209.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-2563
https://notcve.org/view.php?id=CVE-2006-2563
29 May 2006 — The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters. • http://secunia.com/advisories/20337 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-1991
https://notcve.org/view.php?id=CVE-2006-1991
24 Apr 2006 — The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument. La función substr_compare en string.c en PHP 5.1.2 permite a atacantes dependientes del contexto provocar una denegación de servicio (violación de acceso a memoria) a través de un argumento de desplazamiento fuera de los límites. • http://secunia.com/advisories/20052 • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-1990
https://notcve.org/view.php?id=CVE-2006-1990
24 Apr 2006 — Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396. Desbordamiento de entero en la función wordwrap en string.c en PHP 4.4.2 y 5.1.2 podría permitir a atacantes dependientes del contexto ejecutar código arbitrario a través de ciertos ... • ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-1549 – PHP 4/5 - Executor Deep Recursion Remote Denial of Service
https://notcve.org/view.php?id=CVE-2006-1549
10 Apr 2006 — PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected. • https://www.exploit-db.com/exploits/29693 • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-1608 – PHP 4.x - 'copy() Safe_Mode' Bypass
https://notcve.org/view.php?id=CVE-2006-1608
10 Apr 2006 — The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI. • https://www.exploit-db.com/exploits/27596 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-1494 – PHP 4.x - 'tempnam() open_basedir' Restriction Bypass
https://notcve.org/view.php?id=CVE-2006-1494
10 Apr 2006 — Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function. • https://www.exploit-db.com/exploits/27595 •