Loading...
Loading...
The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.
May 16, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-2727
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.