← All CVEs

CVE-2011-1467

medium · 5

Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a related issue to CVE-2010-4409.

5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2011-03-20
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

VendorProductAffected versions
phpphp<= 5.3.5
phpphp1.0
phpphp2.0
phpphp2.0b10
phpphp3.0
phpphp3.0.1
phpphp3.0.2
phpphp3.0.3
phpphp3.0.4
phpphp3.0.5
phpphp3.0.6
phpphp3.0.7
phpphp3.0.8
phpphp3.0.9
phpphp3.0.10
phpphp3.0.11
phpphp3.0.12
phpphp3.0.13
phpphp3.0.14
phpphp3.0.15
phpphp3.0.16
phpphp3.0.17
phpphp3.0.18
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0
phpphp4.0.0
phpphp4.0.1
phpphp4.0.2
phpphp4.0.3
phpphp4.0.4
phpphp4.0.5
phpphp4.0.6
phpphp4.0.7
phpphp4.1.0
phpphp4.1.1
phpphp4.1.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-1467