Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-3319

11
FAUCET Score

CVE-2005-3319 describes a denial-of-service vulnerability affecting PHP 5.x before 5.1.0 and PHP 4.4 before 4.4.1, specifically within the apache2handler SAPI (mod_php). An attacker can trigger a segmentation fault by manipulating the session.save_path option in a .htaccess file or VirtualHost. This vulnerability has a low severity CVSS score of 2.1, indicating a local attack vector with low complexity, resulting in a partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.0.0CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.1:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.1:patch1:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.1:patch2:*:*:*:*:*:*
4.0.2CPE matchmatch criteria
cpe:2.3:a:php:php:4.0.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.1LOW

AV:L/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0059 is in the 81st percentile among its peer group of 2,096 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2005-3319

CVE-2005-3319

References

archives.neohapsis.com / archives/fulldisclosure/2005-10/0491.html
bugs.gentoo.org / show_bug.cgi
docs.info.apple.com / article.html
itrc.hp.com / service/cki/docDisplay.do
lists.apple.com / archives/security-announce/2006/Mar/msg00000.html
marc.info
secunia.com / advisories/17510
secunia.com / advisories/17557
secunia.com / advisories/18198
secunia.com / advisories/19064
secunia.com / advisories/22691
securityreason.com / securityalert/525
exchange.xforce.ibmcloud.com / vulnerabilities/22844
ubuntu.com / usn/usn-232-1
gentoo.org / security/en/glsa/glsa-200511-08.xml
mandriva.com / security/advisories
osvdb.org / 20491
securityfocus.com / bid/15177
securityfocus.com / bid/16907
us-cert.gov / cas/techalerts/TA06-062A.html
US Government Resource
vupen.com / english/advisories/2006/0791
vupen.com / english/advisories/2006/4320