Search/CVE-2007-0909
CVE

CVE-2007-0909

Multiple format string vulnerabilities in PHP before 5.2.1 might allow attackers to execute arbitrary code via format string specifiers to (1) all of the *print functions on 64-bit systems, and (2) the odbc_result_all function.

CVSS v3.1
EPSS
3.30%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 12, 2026
0.05pp
3.25% → 3.30% over 2 tracked changes
Connections
2 relationships
Timeline
disclosure → media coverage
Feb 13, 2007
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026