CVE-2007-4659
- EPSS 3.27%
- Veröffentlicht 04.09.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:31
The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.
CVE-2007-4660
- EPSS 2.61%
- Veröffentlicht 04.09.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:31
Unspecified vulnerability in the chunk_split function in PHP before 5.2.4 has unknown impact and attack vectors, related to an incorrect size calculation.
CVE-2007-4661
- EPSS 2.36%
- Veröffentlicht 04.09.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:31
The chunk_split function in string.c in PHP 5.2.3 does not properly calculate the needed buffer size due to precision loss when performing integer arithmetic with floating point numbers, which has unknown attack vectors and impact, possibly resulting...
CVE-2007-4662
- EPSS 3.38%
- Veröffentlicht 04.09.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:32
Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors.
CVE-2007-4663
- EPSS 2.14%
- Veröffentlicht 04.09.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:32
Directory traversal vulnerability in PHP before 5.2.4 allows attackers to bypass open_basedir restrictions via unspecified vectors involving the glob function.
CVE-2007-4652
- EPSS 0.61%
- Veröffentlicht 04.09.2007 19:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:30
The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.
CVE-2007-3996
- EPSS 4.22%
- Veröffentlicht 04.09.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:43:12
Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a la...
CVE-2007-3997
- EPSS 13.82%
- Veröffentlicht 04.09.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:43:12
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.
- EPSS 2.99%
- Veröffentlicht 04.09.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:43:12
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certai...
CVE-2007-4596
- EPSS 7.78%
- Veröffentlicht 30.08.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:24
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.