NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27657  CVE-2015-6835  The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.    7.5  High  2017-01-19  2016-11-29  View
53880  CVE-2007-1700  The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.    7.5  High  2017-01-07  2012-11-05  View
56772  CVE-2007-4652  The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.    4.4  Medium  2017-01-07  2011-08-23  View
56255  CVE-2007-4124  The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user"s session data, and possibly gain privileges.    4.9  Medium  2017-01-07  2011-03-07  View
58086  CVE-2007-6077  The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.    6.8  Medium  2017-01-07  2012-07-06  View

Page 14505 of 17672, showing 5 records out of 88360 total, starting on record 72521, ending on 72525

Actions