NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27657 | CVE-2015-6835 | The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content. | 2 | 7.5 | High | 2017-01-19 | 2016-11-29 | View | |
| 53880 | CVE-2007-1700 | The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable. | 2 | 7.5 | High | 2017-01-07 | 2012-11-05 | View | |
| 56772 | CVE-2007-4652 | The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink. | 2 | 4.4 | Medium | 2017-01-07 | 2011-08-23 | View | |
| 56255 | CVE-2007-4124 | The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user"s session data, and possibly gain privileges. | 2 | 4.9 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 58086 | CVE-2007-6077 | The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380. | 2 | 6.8 | Medium | 2017-01-07 | 2012-07-06 | View |
Page 14505 of 17672, showing 5 records out of 88360 total, starting on record 72521, ending on 72525