CVE-2016-4346
- EPSS 0.59%
- Veröffentlicht 22.05.2016 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.
CVE-2016-4345
- EPSS 0.41%
- Veröffentlicht 22.05.2016 01:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based bu...
CVE-2016-4344
- EPSS 0.41%
- Veröffentlicht 22.05.2016 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argument to the utf8_encode function, leading to a heap-ba...
CVE-2016-4343
- EPSS 12.89%
- Veröffentlicht 22.05.2016 01:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly ha...
CVE-2016-4342
- EPSS 5.56%
- Veröffentlicht 22.05.2016 01:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other im...
- EPSS 2.16%
- Veröffentlicht 22.05.2016 01:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.
CVE-2015-8879
- EPSS 1.62%
- Veröffentlicht 22.05.2016 01:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 mishandles driver behavior for SQL_WVARCHAR columns, which allows remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging us...
CVE-2015-8878
- EPSS 0.37%
- Veröffentlicht 22.05.2016 01:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that perfor...
CVE-2015-8877
- EPSS 2.32%
- Veröffentlicht 22.05.2016 01:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memo...
CVE-2015-8876
- EPSS 12.62%
- Veröffentlicht 22.05.2016 01:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trig...