CVE-2007-1401
- EPSS 0.1%
- Veröffentlicht 10.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.
CVE-2007-1411
- EPSS 13.42%
- Veröffentlicht 10.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.
- EPSS 15.39%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.
CVE-2007-1376
- EPSS 13.85%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associ...
CVE-2007-1378
- EPSS 0.6%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.
CVE-2007-1379
- EPSS 1.06%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.
- EPSS 12.71%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, w...
CVE-2007-1381
- EPSS 4.73%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers...
- EPSS 2.57%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.
CVE-2007-1285
- EPSS 8.63%
- Veröffentlicht 06.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.