AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-1888

HIGH · CVSS 7.5 EPSS 3.49%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-04-06 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-1888
Severity
HIGH
CVSS
7.5
EPSS
3.49%

Original Filing — NVD Description

Buffer overflow in the sqlite_decode_binary function in src/encode.c in SQLite 2, as used by PHP 4.x through 5.x and other applications, allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter. NOTE: some PHP installations use a bundled version of sqlite without this vulnerability. The SQLite developer has argued that this issue could be due to a misuse of the sqlite_decode_binary() API.