CVE-2016-4540
- EPSS 1.46%
- Veröffentlicht 22.05.2016 01:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact v...
CVE-2016-4539
- EPSS 3.37%
- Veröffentlicht 22.05.2016 01:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other imp...
CVE-2016-4538
- EPSS 4.88%
- Veröffentlicht 22.05.2016 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows rem...
CVE-2016-4537
- EPSS 4.88%
- Veröffentlicht 22.05.2016 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified ot...
CVE-2016-4346
- EPSS 0.59%
- Veröffentlicht 22.05.2016 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
CVE-2016-4342
- EPSS 5.56%
- Veröffentlicht 22.05.2016 01:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other im...
CVE-2015-8866
- EPSS 3.05%
- Veröffentlicht 22.05.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML...
CVE-2016-4348
- EPSS 3.08%
- Veröffentlicht 20.05.2016 14:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.
CVE-2016-3705
- EPSS 1.03%
- Veröffentlicht 17.05.2016 14:08:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and applic...
CVE-2016-3627
- EPSS 0.29%
- Veröffentlicht 17.05.2016 14:08:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML doc...