← All CVEs

CVE-2004-1065

high · 10

Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.

10
CVSS
10.0%
EPSS (exploit prob.)
95th
EPSS percentile
2005-01-10
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
openpkgopenpkg2.1
openpkgopenpkg2.2
openpkgopenpkgcurrent
phpphp3.0
phpphp3.0.1
phpphp3.0.2
phpphp3.0.3
phpphp3.0.4
phpphp3.0.5
phpphp3.0.6
phpphp3.0.7
phpphp3.0.8
phpphp3.0.9
phpphp3.0.10
phpphp3.0.11
phpphp3.0.12
phpphp3.0.13
phpphp3.0.14
phpphp3.0.15
phpphp3.0.16
phpphp3.0.17
phpphp3.0.18
phpphp4.0
phpphp4.0.1
phpphp4.0.1
phpphp4.0.1
phpphp4.0.2
phpphp4.0.3
phpphp4.0.3
phpphp4.0.4
phpphp4.0.5
phpphp4.0.6
phpphp4.0.7
phpphp4.0.7
phpphp4.0.7
phpphp4.0.7
phpphp4.1.0
phpphp4.1.1
phpphp4.1.2
phpphp4.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1065