CVE-2004-1018

CRITICAL ⚠ Exploit

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the s...

Affects 2 products across 2 vendors.

BCS8.92
CVSS 2.010.0
EPSS16.2%
Percentile97th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code.

BSID: BS-2005-GLOBAL-161123-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-1018?
Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code.
What is the CVSS score for CVE-2004-1018?
CVE-2004-1018 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 16.2%.
Is CVE-2004-1018 actively exploited?
Public exploit available for CVE-2004-1018. Exploitation risk elevated.
How do I remediate CVE-2004-1018?
Priority: IMMEDIATE. Advisory: http://www.php.net/release_4_3_10.php PSIRT: [email protected]
What systems are affected by CVE-2004-1018?
CVE-2004-1018 affects: Canonical, Php.
Vulnerability Details
CVE IDCVE-2004-1018
BSIDBS-2005-GLOBAL-161123-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2005-01-10
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Attackers can exploit these vulnerabilities by using a negative offset value to the shmop_write function, or by causing an integer overflow/underflow in the pack or unpack functions.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Canonical Ubuntu Linux
Php Php
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 7875 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Canonical
CVE-2004-1063 10.0 PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multit... CVE-2007-0063 10.0 Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 B... CVE-2008-2663 10.0 Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and ear... CVE-2008-4062 10.0 Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3... CVE-2007-2442 10.0 The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb...
View all Canonical CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →