- EPSS 4.65%
- Veröffentlicht 28.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:10
The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ('\0') byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. NO...
CVE-2007-1718
- EPSS 6.69%
- Veröffentlicht 28.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:10
CRLF injection vulnerability in the mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows remote attackers to inject arbitrary e-mail headers and possibly conduct spam attacks via a control character immediately following folding of...
CVE-2007-1700
- EPSS 9.02%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:08
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbit...
CVE-2007-1701
- EPSS 9.23%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:08
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling se...
CVE-2007-1709
- EPSS 1.98%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:09
Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows context-dependent attackers to execute arbitrary code via a long argument string.
CVE-2007-1710
- EPSS 0.44%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:09
The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a...
CVE-2007-1711
- EPSS 7.63%
- Veröffentlicht 27.03.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:09
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbitrary code by overwriting variables pointing to (1) the GLOBALS array or (2) the session data in _SESSION. NOTE: this issue was in...
CVE-2007-1649
- EPSS 7.21%
- Veröffentlicht 24.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:01
PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.
CVE-2007-1581
- EPSS 7.92%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:52
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting the hash_update_file function via a userspace (1) error or (2) stream handler, which can then be used to destroy and modify in...
CVE-2007-1582
- EPSS 5.92%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:52
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupting certain functions in the GD (ext/gd) extension and unspecified other extensions via a userspace error ...