VDB
CVE-2004-1019
CVE-2004-1019
PUBLISHED
Reported by mitre · Published December 22, 2004
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Dec 22, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Nov 29, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
References
- RHSA-2005:032 vendor-advisoryx_refsource_REDHAT
- php-unserialize-code-execution(18514) vdb-entryx_refsource_XF
- SUSE-SU-2015:0365 vendor-advisoryx_refsource_SUSE
- SUSE-SA:2005:002 vendor-advisoryx_refsource_SUSE
- x_refsource_CONFIRM
- openSUSE-SU-2015:0325 vendor-advisoryx_refsource_SUSE
- oval:org.mitre.oval:def:10511 vdb-entrysignaturex_refsource_OVAL
- RHSA-2005:816 vendor-advisoryx_refsource_REDHAT
- MDKSA-2004:151 vendor-advisoryx_refsource_MANDRAKE
- x_refsource_MISC
- x_refsource_CONFIRM
- FLSA:2344 vendor-advisoryx_refsource_FEDORA
- OpenPKG-SA-2004.053 vendor-advisoryx_refsource_OPENPKG
- HPSBMA01212 vendor-advisoryx_refsource_HP
- RHSA-2004:687 vendor-advisoryx_refsource_REDHAT
- 20041215 Advisory 01/2004: Multiple vulnerabilities in PHP 4/5 mailing-listx_refsource_BUGTRAQ