7.8
CVSSv2

CVE-2007-1883

Published: 06/04/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

PHP 4.0.0 up to and including 4.4.6 and 5.0.0 up to and including 5.2.1 allows context-dependent malicious users to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convert_to_* functions with its input parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.0.0

php php 4.0.4

php php 4.1.1

php php 4.1.2

php php 4.3.1

php php 4.3.10

php php 4.3.7

php php 4.3.8

php php 4.4.6

php php 5.0.0

php php 5.0.1

php php 5.0

php php 5.1.0

php php 5.2.0

php php 5.2.1

php php 4.0.3

php php 4.0.7

php php 4.1.0

php php 4.2

php php 4.3.0

php php 4.3.5

php php 4.3.6

php php 4.4.4

php php 4.4.5

php php 5.1.5

php php 5.1.6

php php 4.0.1

php php 4.0.2

php php 4.2.2

php php 4.2.3

php php 4.3.3

php php 4.3.4

php php 4.4.2

php php 4.4.3

php php 5.0.4

php php 5.0.5

php php 5.1.3

php php 5.1.4

php php 4.0.5

php php 4.0.6

php php 4.2.0

php php 4.2.1

php php 4.3.11

php php 4.3.2

php php 4.3.9

php php 4.4.0

php php 4.4.1

php php 5.0.2

php php 5.0.3

php php 5.1.1

php php 5.1.2