CVE-2015-4605
- EPSS 9.11%
- Veröffentlicht 16.05.2016 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of ...
CVE-2015-4604
- EPSS 9.11%
- Veröffentlicht 16.05.2016 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a den...
- EPSS 8.13%
- Veröffentlicht 16.05.2016 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.
- EPSS 12.86%
- Veröffentlicht 16.05.2016 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a...
CVE-2015-4598
- EPSS 1.45%
- Veröffentlicht 16.05.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument...
CVE-2015-3412
- EPSS 1.01%
- Veröffentlicht 16.05.2016 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_pat...
CVE-2015-3411
- EPSS 0.29%
- Veröffentlicht 16.05.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument ...
CVE-2015-1350
- EPSS 0.07%
- Veröffentlicht 02.05.2016 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a...
CVE-2016-2143
- EPSS 0.17%
- Veröffentlicht 27.04.2016 17:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted appli...
CVE-2016-0666
- EPSS 0.24%
- Veröffentlicht 21.04.2016 10:59:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Secu...