CVE-2007-1001
- EPSS 10.33%
- Veröffentlicht 06.04.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) ...
CVE-2007-1835
- EPSS 0.14%
- Veröffentlicht 03.04.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR default after checking the restrictions, which allows local users to bypass open_basedir restrictions.
CVE-2007-1824
- EPSS 1.89%
- Veröffentlicht 02.04.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the '.' character.
CVE-2007-1825
- EPSS 5.44%
- Veröffentlicht 02.04.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers to execute arbitrary code via a long boundary string in a type.parameters field. NOTE: as of 20070411, it appears that this issue...
CVE-2007-1777
- EPSS 13.86%
- Veröffentlicht 30.03.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, tr...
- EPSS 17.63%
- Veröffentlicht 28.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. NO...
CVE-2007-1718
- EPSS 21.83%
- Veröffentlicht 28.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of...
CVE-2007-1700
- EPSS 4.17%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbit...
CVE-2007-1701
- EPSS 11.35%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling se...
CVE-2007-1709
- EPSS 1.12%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.