CVE
- Id
- 9022
- CVE No.
- CVE-2004-0594
- Status
- Candidate
- Description
- The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.
- Phase
- Assigned (20040623)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 58266 | 9022 | CVE-2004-0594 | BUGTRAQ:20040713 Advisory 11/2004: PHP memory_limit remote vulnerability | View |
| 58267 | 9022 | CVE-2004-0594 | URL:http://marc.info/?l=bugtraq&m=108981780109154&w=2 | View |
| 58268 | 9022 | CVE-2004-0594 | FULLDISC:20040714 Advisory 11/2004: PHP memory_limit remote vulnerability | View |
| 58269 | 9022 | CVE-2004-0594 | URL:http://lists.grok.org.uk/pipermail/full-disclosure/2004-July/023908.html | View |
| 58270 | 9022 | CVE-2004-0594 | BUGTRAQ:20040714 TSSA-2004-013 - php | View |
| 58271 | 9022 | CVE-2004-0594 | URL:http://marc.info/?l=bugtraq&m=108982983426031&w=2 | View |
| 58272 | 9022 | CVE-2004-0594 | CONECTIVA:CLA-2004:847 | View |
| 58273 | 9022 | CVE-2004-0594 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000847 | View |
| 58274 | 9022 | CVE-2004-0594 | DEBIAN:DSA-531 | View |
| 58275 | 9022 | CVE-2004-0594 | URL:http://www.debian.org/security/2004/dsa-531 | View |
| 58276 | 9022 | CVE-2004-0594 | DEBIAN:DSA-669 | View |
| 58277 | 9022 | CVE-2004-0594 | URL:http://www.debian.org/security/2005/dsa-669 | View |
| 58278 | 9022 | CVE-2004-0594 | GENTOO:GLSA-200407-13 | View |
| 58279 | 9022 | CVE-2004-0594 | URL:http://www.gentoo.org/security/en/glsa/glsa-200407-13.xml | View |
| 58280 | 9022 | CVE-2004-0594 | HP:SSRT4777 | View |
| 58281 | 9022 | CVE-2004-0594 | URL:http://marc.info/?l=bugtraq&m=109181600614477&w=2 | View |
| 58282 | 9022 | CVE-2004-0594 | MANDRAKE:MDKSA-2004:068 | View |
| 58283 | 9022 | CVE-2004-0594 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:068 | View |
| 58284 | 9022 | CVE-2004-0594 | REDHAT:RHSA-2004:392 | View |
| 58285 | 9022 | CVE-2004-0594 | URL:http://www.redhat.com/support/errata/RHSA-2004-392.html | View |
| 58286 | 9022 | CVE-2004-0594 | REDHAT:RHSA-2004:395 | View |
| 58287 | 9022 | CVE-2004-0594 | URL:http://www.redhat.com/support/errata/RHSA-2004-395.html | View |
| 58288 | 9022 | CVE-2004-0594 | REDHAT:RHSA-2004:405 | View |
| 58289 | 9022 | CVE-2004-0594 | URL:http://www.redhat.com/support/errata/RHSA-2004-405.html | View |
| 58290 | 9022 | CVE-2004-0594 | REDHAT:RHSA-2005:816 | View |
| 58291 | 9022 | CVE-2004-0594 | URL:http://www.redhat.com/support/errata/RHSA-2005-816.html | View |
| 58292 | 9022 | CVE-2004-0594 | SUSE:SUSE-SA:2004:021 | View |
| 58293 | 9022 | CVE-2004-0594 | URL:http://www.novell.com/linux/security/advisories/2004_21_php4.html | View |
| 58294 | 9022 | CVE-2004-0594 | TRUSTIX:2004-0039 | View |
| 58295 | 9022 | CVE-2004-0594 | URL:http://www.trustix.org/errata/2004/0039/ | View |
| 58296 | 9022 | CVE-2004-0594 | BUGTRAQ:20040722 [OpenPKG-SA-2004.034] OpenPKG Security Advisory (php) | View |
| 58297 | 9022 | CVE-2004-0594 | URL:http://marc.info/?l=bugtraq&m=109051444105182&w=2 | View |
| 58298 | 9022 | CVE-2004-0594 | BID:10725 | View |
| 58299 | 9022 | CVE-2004-0594 | URL:http://www.securityfocus.com/bid/10725 | View |
| 58300 | 9022 | CVE-2004-0594 | OVAL:oval:org.mitre.oval:def:10896 | View |
| 58301 | 9022 | CVE-2004-0594 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10896 | View |
| 58302 | 9022 | CVE-2004-0594 | XF:php-memorylimit-code-execution(16693) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62942 | JVNDB-2004-000284 | PHP の strip_tags() 関数におけるクロスサイトスクリプティングの脆弱性 | PHP に実装されている strip_tags() 関数には、" " 等の文字列が含まれているタグが適切に取り除かれない不備があり、不正なタグを含む文字列を入力することにより、 strip_tags() によるチェックを回避して script タグを挿入することにより、クロスサイトスクリプティングの脆弱性が存在します。 | CVE-2004-0595 | 9022 | 6.8 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000284.html | View |