CVE-2003-0166 – PHP 4.x - 'socket_recv()' Signed Integer Memory Corruption
https://notcve.org/view.php?id=CVE-2003-0166
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions. • https://www.exploit-db.com/exploits/22425 https://www.exploit-db.com/exploits/22426 https://www.exploit-db.com/exploits/22419 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000691 http://marc.info/?l=bugtraq&m=104869828526885&w=2 http://marc.info/?l=bugtraq&m=104878100719467&w=2 http://marc.info/?l=bugtraq&m=104931415307111&w=2 http://www.securityfocus.com/bid/7197 http://www.securityfocus.com/bid/7198 •
CVE-2002-1396
https://notcve.org/view.php?id=CVE-2002-1396
Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code. Desbordamiento de búfer basado en la pila en la función wordwrap en PHP posteriores a 4.1.2 y anteriores a 4.3.0 puede permitir a atacantes causar una denegación de servicio o ejecutar código arbitrario. • http://archives.neohapsis.com/archives/linux/engarde/2003-q1/0003.html http://bugs.php.net/bug.php?id=20927 http://marc.info/?l=bugtraq&m=104102689503192&w=2 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:019 http://www.novell.com/linux/security/advisories/2003_009_mod_php4.html http://www.redhat.com/support/errata/RHSA-2003-017.html http://www.securityfocus.com/advisories/4862 http://www.securityfocus.com/bid/6488 https://exchange.xforce.ibmcloud.com/vuln •
CVE-2002-2214
https://notcve.org/view.php?id=CVE-2002-2214
The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header. • http://bugs.php.net/bug.php?id=15595 http://secunia.com/advisories/21202 http://www.redhat.com/support/errata/RHSA-2006-0567.html https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040 https://access.redhat.com/security/cve/CVE-2002-2214 https://bugzilla.redhat.com/show_bug.cgi?id=1616931 •
CVE-2002-1954 – PHP 4 - 'PHPInfo()' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2002-1954
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php. • https://www.exploit-db.com/exploits/22725 http://archives.neohapsis.com/archives/bugtraq/2003-06/0027.html http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0021.html http://www.iss.net/security_center/static/10355.php http://www.techie.hopto.org/vulns/2002-36.txt •
CVE-2002-2215
https://notcve.org/view.php?id=CVE-2002-2215
The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822_write_address function. • http://bugs.php.net/bug.php?id=19280 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175040 https://access.redhat.com/security/cve/CVE-2002-2215 https://bugzilla.redhat.com/show_bug.cgi?id=1616932 •