CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2008-5557

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0510%
EPSS Percentile26.55th
Published2008年12月23日
Last Modified2026年4月23日

Vulnerability Description

Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.

Affected Platforms (CPE)

📦
Php

Php

= 4.3.0
📦
Php

Php

= 4.3.1
📦
Php

Php

= 4.3.2
📦
Php

Php

= 4.3.3
📦
Php

Php

= 4.3.4
📦
Php

Php

= 4.3.5
📦
Php

Php

= 4.3.6
📦
Php

Php

= 4.3.7
📦
Php

Php

= 4.3.8
📦
Php

Php

= 4.3.9
📦
Php

Php

= 4.3.10
📦
Php

Php

= 4.3.11
📦
Php

Php

= 4.4.0
📦
Php

Php

= 4.4.1
📦
Php

Php

= 4.4.2
📦
Php

Php

= 4.4.3
📦
Php

Php

= 4.4.4
📦
Php

Php

= 4.4.5
📦
Php

Php

= 4.4.6
📦
Php

Php

= 4.4.7
📦
Php

Php

= 4.4.8
📦
Php

Php

= 4.4.9
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.0
📦
Php

Php

= 5.0.1
📦
Php

Php

= 5.0.2
📦
Php

Php

= 5.0.3
📦
Php

Php

= 5.0.4
📦
Php

Php

= 5.0.5
📦
Php

Php

= 5.1.0
📦
Php

Php

= 5.1.1
📦
Php

Php

= 5.1.2
📦
Php

Php

= 5.1.3
📦
Php

Php

= 5.1.4
📦
Php

Php

= 5.1.5
📦
Php

Php

= 5.1.6
📦
Php

Php

= 5.2.0
📦
Php

Php

= 5.2.1
📦
Php

Php

= 5.2.2
📦
Php

Php

= 5.2.3
📦
Php

Php

= 5.2.4
📦
Php

Php

= 5.2.5
📦
Php

Php

= 5.2.6

References & Advisories

相關漏洞威脅