CyberSec.Space Logo
Back to CVE Browser

CVE-2008-5557

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0510%
EPSS Percentile26.55th
PublishedDec 23, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.

Affected Platforms (CPE)

πŸ“¦
Php

Php

= 4.3.0
πŸ“¦
Php

Php

= 4.3.1
πŸ“¦
Php

Php

= 4.3.2
πŸ“¦
Php

Php

= 4.3.3
πŸ“¦
Php

Php

= 4.3.4
πŸ“¦
Php

Php

= 4.3.5
πŸ“¦
Php

Php

= 4.3.6
πŸ“¦
Php

Php

= 4.3.7
πŸ“¦
Php

Php

= 4.3.8
πŸ“¦
Php

Php

= 4.3.9
πŸ“¦
Php

Php

= 4.3.10
πŸ“¦
Php

Php

= 4.3.11
πŸ“¦
Php

Php

= 4.4.0
πŸ“¦
Php

Php

= 4.4.1
πŸ“¦
Php

Php

= 4.4.2
πŸ“¦
Php

Php

= 4.4.3
πŸ“¦
Php

Php

= 4.4.4
πŸ“¦
Php

Php

= 4.4.5
πŸ“¦
Php

Php

= 4.4.6
πŸ“¦
Php

Php

= 4.4.7
πŸ“¦
Php

Php

= 4.4.8
πŸ“¦
Php

Php

= 4.4.9
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.0
πŸ“¦
Php

Php

= 5.0.1
πŸ“¦
Php

Php

= 5.0.2
πŸ“¦
Php

Php

= 5.0.3
πŸ“¦
Php

Php

= 5.0.4
πŸ“¦
Php

Php

= 5.0.5
πŸ“¦
Php

Php

= 5.1.0
πŸ“¦
Php

Php

= 5.1.1
πŸ“¦
Php

Php

= 5.1.2
πŸ“¦
Php

Php

= 5.1.3
πŸ“¦
Php

Php

= 5.1.4
πŸ“¦
Php

Php

= 5.1.5
πŸ“¦
Php

Php

= 5.1.6
πŸ“¦
Php

Php

= 5.2.0
πŸ“¦
Php

Php

= 5.2.1
πŸ“¦
Php

Php

= 5.2.2
πŸ“¦
Php

Php

= 5.2.3
πŸ“¦
Php

Php

= 5.2.4
πŸ“¦
Php

Php

= 5.2.5
πŸ“¦
Php

Php

= 5.2.6

References & Advisories

Related Vulnerabilities