peter bassill · operator
$ cve CVE-2007-1001 JSON

CVE-2007-1001 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 8.3% (pctl 95)

Patch early

A public exploit exists.

Description

Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS8.32% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2007-04-06
Last modified2026-06-16

Affected (1)

VendorProduct
phpphp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD