cbcvebase.
CVE-2007-1285
published 2007-03-06

CVE-2007-1285: The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply…

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
18.16%
96.9th percentile
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
novellsuse_linux
novellsuse_linux
phpphp<= 5.2.3
phpphp>= 4.0.0 < 4.4.74.4.7
phpphp>= 5.0.0 < 5.2.25.2.2
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.