2.6
CVSSv2

CVE-2007-2727

Published: 16/05/2007 Updated: 07/11/2022
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP prior to 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent malicious users to decrypt certain data more easily because of the guessable encryption keys.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.9

php php 4.2.0

php php 4.1.0

php php 4.3.4

php php 4.0.4

php php 4.3.0

php php 4.0.5

php php 4.3.6

php php 4.0.7

php php 4.3.11

php php 4.3.2

php php 4.2.2

php php 4.0.3

php php 4.3.7

php php 4.0.6

php php 4.1.2

php php 4.0.1

php php 4.3.3

php php 4.1.1

php php 4.3.1

php php 4.3.10

php php 4.0.2

php php 4.2.3

php php 4.2.1

php php 4.3.8

php php 4.3.5

php php