Vulnerabilities > PHP > PHP > 4.0.0

DATE CVE VULNERABILITY TITLE RISK
2007-03-20 CVE-2007-1521 Unspecified vulnerability in PHP
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbitrary code by interrupting the session_regenerate_id function, as demonstrated by calling a userspace error handler or triggering a memory limit violation.
network
php
6.8
2007-03-16 CVE-2007-1484 Unspecified vulnerability in PHP
The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.
local
low complexity
php
4.6
2007-03-16 CVE-2007-1475 Remote Buffer Overflow vulnerability in PHP Interbase Extension
Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.
php
5.4
2007-03-14 CVE-2007-1461 Permissions, Privileges, and Access Controls vulnerability in PHP
The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.
network
low complexity
php CWE-264
7.8
2007-03-14 CVE-2007-1460 Permissions, Privileges, and Access Controls vulnerability in PHP
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.
network
low complexity
php CWE-264
5.0
2007-03-12 CVE-2007-1413 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in PHP
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id).
network
low complexity
php CWE-119
7.5
2007-03-10 CVE-2007-1411 Local Buffer Overflow vulnerability in PHP MSSQL_Connect
Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.
network
php
6.8
2007-03-10 CVE-2007-1380 Unspecified vulnerability in PHP
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.
network
low complexity
php
5.0
2007-03-10 CVE-2007-1379 Unspecified vulnerability in PHP
The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.
network
high complexity
php
5.1
2007-03-10 CVE-2007-1378 Unspecified vulnerability in PHP
The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to write to arbitrary memory locations via the result_id and length arguments.
network
high complexity
php
5.1