5
CVSSv2

CVE-2007-2728

Published: 16/05/2007 Updated: 31/03/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php -

canonical ubuntu linux 6.06

canonical ubuntu linux 6.10

canonical ubuntu linux 7.04

Vendor Advisories

It was discovered that the PHP xmlrpc extension did not correctly check heap memory allocation sizes A remote attacker could send a specially crafted request to a PHP application using xmlrpc and execute arbitrary code as the Apache user (CVE-2007-1864) ...