CVE-2007-1583
- EPSS 5.24%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:52
The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with...
CVE-2007-1584
- EPSS 5.25%
- Veröffentlicht 21.03.2007 23:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:52
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by passing an all-whitespace string to this function, which causes it to write '\0' characters in whitespace that precedes the string.
CVE-2007-1521
- EPSS 8.49%
- Veröffentlicht 20.03.2007 20:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:45
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a...
CVE-2007-1522
- EPSS 6.61%
- Veröffentlicht 20.03.2007 20:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:45
Double free vulnerability in the session extension in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to execute arbitrary code via illegal characters in a session identifier, which is rejected by an internal session storage module, which call...
CVE-2007-1475
- EPSS 2.37%
- Veröffentlicht 16.03.2007 21:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:39
Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.
CVE-2007-1484
- EPSS 1.11%
- Veröffentlicht 16.03.2007 21:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:40
The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operatio...
- EPSS 5.15%
- Veröffentlicht 14.03.2007 18:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:36
The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.
CVE-2007-1453
- EPSS 9.52%
- Veröffentlicht 14.03.2007 18:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:36
Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes...
CVE-2007-1454
- EPSS 1.3%
- Veröffentlicht 14.03.2007 18:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:36
ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by...
- EPSS 1.92%
- Veröffentlicht 14.03.2007 18:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:37
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.