CVE-2017-5340
- EPSS 7.14%
- Published 11.01.2017 06:59:00
- Last modified 20.04.2025 01:37:25
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory a...
CVE-2014-9912
- EPSS 1.16%
- Published 04.01.2017 20:59:00
- Last modified 12.04.2025 10:46:40
The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly restrict calls to the ICU uresbund.cpp component, which allows remote attackers to cause ...
CVE-2016-9137
- EPSS 0.94%
- Published 04.01.2017 20:59:00
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data ...
CVE-2016-9138
- EPSS 2.48%
- Published 04.01.2017 20:59:00
- Last modified 12.04.2025 10:46:40
PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated b...
CVE-2016-9934
- EPSS 11.58%
- Published 04.01.2017 20:59:00
- Last modified 12.04.2025 10:46:40
ext/wddx/wddx.c in PHP before 5.6.28 and 7.x before 7.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted serialized data in a wddxPacket XML document, as demonstrated by a PDORow string.
CVE-2016-9935
- EPSS 4.39%
- Published 04.01.2017 20:59:00
- Last modified 12.04.2025 10:46:40
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty bo...
CVE-2016-9936
- EPSS 0.7%
- Published 04.01.2017 20:59:00
- Last modified 12.04.2025 10:46:40
The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exist...
CVE-2016-7568
- EPSS 1.02%
- Published 28.09.2016 20:59:02
- Last modified 12.04.2025 10:46:40
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspe...
CVE-2016-7418
- EPSS 2.32%
- Published 17.09.2016 21:59:10
- Last modified 12.04.2025 10:46:40
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) or possibly have unspecified other impact via an inc...
CVE-2016-7417
- EPSS 2.52%
- Published 17.09.2016 21:59:09
- Last modified 12.04.2025 10:46:40
ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impac...