CVE-2007-1285 describes a denial-of-service vulnerability in the Zend Engine of PHP versions 4.x before 4.4.7 and 5.x before 5.2.2, impacting products from vendors like Canonical, Novell, and Red Hat. This high-severity vulnerability (CVSS 7.5) allows remote attackers to crash PHP via deeply nested arrays, leading to stack exhaustion during variable destruction. While there is an ExploitDB entry (EDB-29692) detailing a remote DoS, the vulnerability is not listed on the KEV catalog, has no Metasploit or Nuclei modules, and shows no active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.4.7CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.2.2CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
7.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux:10.0:*:*:*:*:*:*:* | ||
10.1CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux:10.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.