Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-1889

Integer signedness error in the _zend_mm_alloc_int function in the Zend Memory Manager in PHP 5.2.0 allows remote attackers to execute arbitrary code via a large emalloc request, related to an incorrect signed long cast, as demonstrated via the HTTP SOAP client in PHP, and via a call to msg_receive with the largest positive integer value of maxsize.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 87.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2007-1889
  • Php » Php » Version: 5.2.0
    cpe:2.3:a:php:php:5.2.0


Contact Us

Shodan ® - All rights reserved