7.5
CVSSv2

CVE-2011-1153

Published: 16/03/2011 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple format string vulnerabilities in phar_object.c in the phar extension in PHP 5.3.5 and previous versions allow context-dependent malicious users to obtain sensitive information from process memory, cause a denial of service (memory corruption), or possibly execute arbitrary code via format string specifiers in an argument to a class method, leading to an incorrect zend_throw_exception_ex call.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.3

php php 4.3.6

php php 4.4.7

php php 5.0.0

php php 5.2.8

php php 4.4.0

php php 5.0.4

php php 5.2.9

php php 5.0.3

php php 5.1.6

php php 5.2.0

php php 2.0

php php 4.4.8

php php 3.0.10

php php 3.0.13

php php 3.0.3

php php 3.0.15

php php 3.0.8

php php 3.0.5

php php 4.0.6

php php 4.0.5

php php 5.2.14

php php 4.0.7

php php 4.3.11

php php 4.3.4

php php 4.4.5

php php 4.4.6

php php 4.3.8

php php 4.3.9

php php 4.4.4

php php 5.0.5

php php 5.2.12

php php 5.2.13

php php 5.2.2

php php 1.0

php php 2.0b10

php php 5.3.0

php php 3.0.11

php php 3.0.18

php php 3.0.4

php php 3.0.9

php php 3.0.7

php php 4.0

php php 4.1.1

php php 4.1.0

php php 4.3.10

php php 4.3.5

php php 4.2.1

php php 4.2.0

php php 4.3.7

php php 5.2.6

php php 4.4.1

php php 5.1.3

php php 5.1.2

php php 5.0.2

php php 5.0.1

php php 5.1.4

php php 5.1.5

php php 4.4.9

php php 5.2.10

php php 3.0.12

php php 3.0.1

php php 3.0.14

php php 3.0.17

php php 3.0.6

php php 4.0.1

php php 4.0.4

php php 4.0.3

php php 5.3.1

php php 5.3.2

php php 4.3.1

php php 4.3.2

php php 4.2.3

php php 4.2.2

php php 5.2.11

php php 5.2.5

php php 4.4.2

php php 4.4.3

php php 5.1.1

php php 5.1.0

php php 5.2.3

php php 5.2.1

php php 5.2.4

php php 4.3.0

php php 3.0

php php 3.0.2

php php 3.0.16

php php 4.0.0

php php 4.0.2

php php 4.1.2

php php 5.3.3

php php 5.3.4

php php

Vendor Advisories

Several vulnerabilities were discovered in PHP, which could lead to denial of service or potentially the execution of arbitrary code CVE-2010-2531 An information leak was found in the var_export() function CVE-2011-0421 The Zip module could crash CVE-2011-0708 An integer overflow was discovered in the Exif module CVE-2011-1466 An i ...
USN 1126-1 introduced two regressions in PHP ...
Multiple vulnerabilities in PHP ...