CVE-2007-1379
- EPSS 1.63%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:28
The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.
- EPSS 9.08%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:28
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, w...
CVE-2007-1381
- EPSS 9.07%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:28
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers...
- EPSS 15.2%
- Veröffentlicht 10.03.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:28
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.
CVE-2007-1285
- EPSS 18.16%
- Veröffentlicht 06.03.2007 20:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:17
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
CVE-2007-1286
- EPSS 40.44%
- Veröffentlicht 06.03.2007 20:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:17
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.
CVE-2007-1287
- EPSS 3.17%
- Veröffentlicht 06.03.2007 20:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:17
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct cross-site scripting (XSS) attacks via GET, POST, or COOKIE array values, which are not escaped in the phpinfo output, as origina...
CVE-2007-0988
- EPSS 2.31%
- Veröffentlicht 20.02.2007 17:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:42
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only caus...
CVE-2007-0905
- EPSS 2.45%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:31
PHP before 5.2.1 allows attackers to bypass safe_mode and open_basedir restrictions via unspecified vectors in the session extension. NOTE: it is possible that this issue is a duplicate of CVE-2006-6383.
CVE-2007-0906
- EPSS 5.49%
- Veröffentlicht 13.02.2007 23:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:31
Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip, (3) imap, and (4) sqlite extensions; (5) stream filters; and the (6) s...