VDB
CVE-2007-2844
CVE-2007-2844
PUBLISHED
CVSS 9.300000190734863 CRITICAL
PHP 4.x and 5.x before 5.2.1, when running on multi-threaded systems, does not ensure thread safety for libc crypt function calls using protection schemes such as a mutex, which creates race conditions that allow remote attackers to overwrite internal program memory and gain system access.
EPSS 0.95% · 76.8th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
0.95%
76.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| php | php | 4.0.4, 4.0, 4.0 |
| n/a | n/a | * |
Timeline
- May 24, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score