Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-1285

37
FAUCET Score

CVE-2007-1285 describes a denial-of-service vulnerability in the Zend Engine of PHP versions 4.x before 4.4.7 and 5.x before 5.2.2, impacting products from vendors like Canonical, Novell, and Red Hat. This high-severity vulnerability (CVSS 7.5) allows remote attackers to crash PHP via deeply nested arrays, leading to stack exhaustion during variable destruction. While there is an ExploitDB entry (EDB-29692) detailing a remote DoS, the vulnerability is not listed on the KEV catalog, has no Metasploit or Nuclei modules, and shows no active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.0, < 4.4.7CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.2.2CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
7.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:*
10.1CPE matchmatch criteria
cpe:2.3:o:novell:suse_linux:10.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
18.16%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-29692 · Mar 1, 2007
This CVE's current EPSS score of 0.1816 is in the 95th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: php-0:4.1.2-2.17
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: php-0:4.3.2-40.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: php-0:4.3.9-3.22.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php-0:5.1.6-7.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: php-0:5.1.6-3.el4s1.6
View patch
redhatpatch availablevia redhat_api
Product: Stronghold 4.0 for RHEL 2.1ASFixed in: stronghold-php-0:4.1.2-15
View patch

Vendor Advisories (1)

redhatCVE-2007-1285Moderate

security flaw

Mar 1, 2007

References

lists.opensuse.org / opensuse-security-announce/2007-07/msg00006.html
Mailing List
rhn.redhat.com / errata/RHSA-2007-0154.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2007-0155.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2007-0163.html
Broken Link
secunia.com / advisories/24909
Broken LinkVendor Advisory
secunia.com / advisories/24910
Broken LinkVendor Advisory
secunia.com / advisories/24924
Broken LinkVendor Advisory
secunia.com / advisories/24941
Broken LinkVendor Advisory
secunia.com / advisories/24945
Broken LinkVendor Advisory
secunia.com / advisories/25445
Broken LinkVendor Advisory
secunia.com / advisories/26048
Broken LinkVendor Advisory
secunia.com / advisories/26642
Broken LinkVendor Advisory
secunia.com / advisories/27864
Broken LinkVendor Advisory
secunia.com / advisories/28936
Broken LinkVendor Advisory
security.gentoo.org / glsa/glsa-200705-19.xml
Third Party Advisory
issues.rpath.com / browse/RPL-1268
Broken Link
slackware.com / security/viewer.php
Broken Link
launchpad.net / bugs/173043
ExploitIssue Tracking
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11017
Broken Link
usn.ubuntu.com / 549-1
Broken Link
us2.php.net / releases/4_4_7.php
Release Notes
us2.php.net / releases/5_2_2.php
Release Notes
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
osvdb.org / 32769
Broken Link
php.net / ChangeLog-4.php
Release Notes
php.net / ChangeLog-5.php
Release Notes
php.net / releases/4_4_8.php
Release Notes
php.net / releases/5_2_4.php
Release Notes
php-security.org / MOPB/MOPB-03-2007.html
Broken LinkExploitVendor Advisory
redhat.com / support/errata/RHSA-2007-0082.html
Broken Link
redhat.com / support/errata/RHSA-2007-0162.html
Broken Link
securityfocus.com / archive/1/466166/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/22764
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-549-2
Third Party Advisory