The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, which might allow context-dependent attackers to execute arbitrary code.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-1375
http://www.securityfocus.com/bid/22833