Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-1990

Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.039
EPSS Ranking 87.8%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2006-1990
  • Php » Php » Version: 4.4.2
    cpe:2.3:a:php:php:4.4.2
  • Php » Php » Version: 5.1.2
    cpe:2.3:a:php:php:5.1.2


Contact Us

Shodan ® - All rights reserved