Lucene search

K
cveMitreCVE-2010-1914
HistoryMay 12, 2010 - 11:46 a.m.

CVE-2010-1914

2010-05-1211:46:40
CWE-200
mitre
web.nvd.nist.gov
36
In Wild
cve-2010-1914
zend engine
php
security
vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

69.6%

The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_function), or (3) ZEND_SR opcode (shift_right_function), related to the convert_to_long_base function.

Affected configurations

Nvd
Node
phpphpMatch5.2.0
OR
phpphpMatch5.2.1
OR
phpphpMatch5.2.2
OR
phpphpMatch5.2.3
OR
phpphpMatch5.2.4
OR
phpphpMatch5.2.5
OR
phpphpMatch5.2.6
OR
phpphpMatch5.2.7
OR
phpphpMatch5.2.8
OR
phpphpMatch5.2.9
OR
phpphpMatch5.2.10
OR
phpphpMatch5.2.11
OR
phpphpMatch5.2.12
OR
phpphpMatch5.3.0
OR
phpphpMatch5.3.1
OR
phpphpMatch5.3.2
VendorProductVersionCPE
phpphp5.2.0cpe:2.3:a:php:php:5.2.0:*:*:*:*:*:*:*
phpphp5.2.1cpe:2.3:a:php:php:5.2.1:*:*:*:*:*:*:*
phpphp5.2.2cpe:2.3:a:php:php:5.2.2:*:*:*:*:*:*:*
phpphp5.2.3cpe:2.3:a:php:php:5.2.3:*:*:*:*:*:*:*
phpphp5.2.4cpe:2.3:a:php:php:5.2.4:*:*:*:*:*:*:*
phpphp5.2.5cpe:2.3:a:php:php:5.2.5:*:*:*:*:*:*:*
phpphp5.2.6cpe:2.3:a:php:php:5.2.6:*:*:*:*:*:*:*
phpphp5.2.7cpe:2.3:a:php:php:5.2.7:*:*:*:*:*:*:*
phpphp5.2.8cpe:2.3:a:php:php:5.2.8:*:*:*:*:*:*:*
phpphp5.2.9cpe:2.3:a:php:php:5.2.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

69.6%