{
    "id": "CVE-2007-1285",
    "published": "2007-03-06 20:19:00",
    "last_modified": "2026-06-16 22:37:17",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "cwe": "CWE-674",
    "description": "The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.",
    "epss_score": "0.18162",
    "epss_percentile": "0.97117",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-30 18:17:06",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "canonical",
            "product": "ubuntu_linux"
        },
        {
            "vendor": "novell",
            "product": "suse_linux"
        },
        {
            "vendor": "php",
            "product": "php"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_desktop"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_workstation"
        },
        {
            "vendor": "suse",
            "product": "linux_enterprise_server"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "29692",
            "title": "PHP 3/4/5 - ZendEngine Variable Destruction Remote Denial of Service",
            "date": "2007-03-01",
            "url": "https://www.exploit-db.com/exploits/29692"
        }
    ],
    "refs_list": [
        "http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html",
        "http://rhn.redhat.com/errata/RHSA-2007-0154.html",
        "http://rhn.redhat.com/errata/RHSA-2007-0155.html",
        "http://rhn.redhat.com/errata/RHSA-2007-0163.html",
        "http://secunia.com/advisories/24909",
        "http://secunia.com/advisories/24910",
        "http://secunia.com/advisories/24924",
        "http://secunia.com/advisories/24941",
        "http://secunia.com/advisories/24945",
        "http://secunia.com/advisories/25445",
        "http://secunia.com/advisories/26048",
        "http://secunia.com/advisories/26642",
        "http://secunia.com/advisories/27864",
        "http://secunia.com/advisories/28936",
        "http://security.gentoo.org/glsa/glsa-200705-19.xml",
        "http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.335136",
        "http://us2.php.net/releases/4_4_7.php",
        "http://us2.php.net/releases/5_2_2.php",
        "http://www.mandriva.com/security/advisories?name=MDKSA-2007:087",
        "http://www.mandriva.com/security/advisories?name=MDKSA-2007:088",
        "http://www.mandriva.com/security/advisories?name=MDKSA-2007:089",
        "http://www.mandriva.com/security/advisories?name=MDKSA-2007:090",
        "http://www.osvdb.org/32769",
        "http://www.php-security.org/MOPB/MOPB-03-2007.html",
        "http://www.php.net/ChangeLog-4.php"
    ]
}