CVE-2007-1710
- EPSS 0.09%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a...
CVE-2007-1711
- EPSS 13.84%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was in...
CVE-2007-1649
- EPSS 6.79%
- Veröffentlicht 24.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.
CVE-2007-1581
- EPSS 10.45%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify in...
CVE-2007-1582
- EPSS 3.27%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error ...
CVE-2007-1583
- EPSS 21.39%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with...
CVE-2007-1584
- EPSS 3.13%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.
CVE-2007-1521
- EPSS 15.26%
- Veröffentlicht 20.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a...
CVE-2007-1522
- EPSS 8.01%
- Veröffentlicht 20.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which call...
CVE-2007-1475
- EPSS 1.7%
- Veröffentlicht 16.03.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.